<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-90817 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-90817/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 10:11:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-90817/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Remote Code Execution in Vanderbilt REDCap via Survey Passthru</title><link>https://feed.craftedsignal.io/briefs/2026-09-redcap-rce/</link><pubDate>Thu, 24 Sep 2026 10:11:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-redcap-rce/</guid><description>A critical unauthenticated RCE vulnerability (CVE-2026-90817) in Vanderbilt REDCap allows attackers to bypass routing restrictions through the '__passthru' parameter, enabling unauthorized access to administrative controllers.</description><content:encoded><![CDATA[<p>CVE-2026-90817 is a critical remote code execution (RCE) vulnerability affecting Vanderbilt REDCap versions 13.3.0 and later. The vulnerability stems from an insecure implementation of the survey passthrough ('__passthru') routing mechanism. By manipulating this parameter within a public survey context, an unauthenticated attacker can force the application to route requests to restricted internal controllers, specifically the Data Import module. This improper routing, combined with insecure file-path or stream handling, allows for the execution of arbitrary code on the underlying web server. While the vulnerability requires a valid public survey hash ('s=') to trigger the full chain, the widespread use of public-facing surveys in academic and clinical research environments significantly increases the attack surface. Organizations using REDCap are strongly urged to patch to the identified LTS or standard releases immediately.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS score of 9.8, indicating high potential for full system compromise. If exploited, attackers can gain unauthorized remote code execution, leading to data exfiltration of sensitive research and patient information, lateral movement within the hosting network, and loss of integrity for the affected REDCap research databases. The vulnerability impacts numerous academic, research, and healthcare institutions that rely on REDCap for data collection.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all affected REDCap instances to the patched versions: 16.0.49 LTS, 17.3.10 LTS, or 17.4.4 Standard, as specified by the vendor.</li>
<li>Deploy the Sigma rules provided in this brief to detect scanning and exploitation attempts targeting the '__passthru' parameter.</li>
<li>Monitor web server logs for suspicious HTTP requests containing '__passthru' directed at administrative or data import URI stems.</li>
<li>Restrict public access to survey endpoints and implement WAF rules to sanitize or block requests containing unusual path traversal or controller manipulation strings.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve-2026-90817</category><category>remote-code-execution</category><category>vulnerability</category><category>webserver</category></item></channel></rss>