External risk intelligence

RECAP Unauthenticated Remote Code Execution via Survey Routing and Data Import.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90817

The vulnerability exists in a public survey context of the REDCap platform. Since public surveys are designed to be accessible to external users via the internet for data collection, the attack surface is commonly exposed as an internet-facing web interface.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical remote code execution vulnerability has been identified in the REDCap platform's survey and data import functionalities, potentially allowing unauthenticated attackers to execute arbitrary code on servers. The issue arises from manipulating HTTP requests and providing a crafted file path during import handling, which could compromise server security.

  • Unauthenticated code execution threat in survey data handling.
  • Significant impact if exploited, affecting server integrity.
  • Verify REDCap exposure and potential impact on operations.

Attack Path

How an attacker could exploit the issue

An attacker could achieve remote code execution on the REDCap server by sending specially crafted HTTP requests. This attack targets the survey passthrough routing and Data Import logic. By manipulating requests to access unintended controller routes from a public survey, and then providing a crafted file-path or stream parameter during data import, an unauthenticated attacker could trigger the vulnerability. Successful exploitation allows arbitrary code to be run on the server, provided the attacker knows a valid public survey hash.

  • Entry condition: Public survey hash known.
  • Trigger point: Manipulated HTTP requests and crafted import parameters.
  • Resulting risk: Arbitrary code execution on server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code on the REDCap server by manipulating HTTP requests, provided they know a valid public survey hash. This could affect the integrity and availability of the REDCap server itself.

  • REDCap server code execution.
  • Malicious HTTP requests and crafted file paths.
  • Server compromise and unauthorized actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for REDCap instances, including application administrators and infrastructure support, must first identify all deployed REDCap environments and confirm exposure. Understanding which surveys are public and accessible via a hash is critical for assessing risk. Subsequent steps will involve coordinating with the vendor and planning remediation during a maintenance window, prioritizing instances with greater exposure or business criticality.

  • Own REDCap instance and survey exposure.
  • Verify public survey hash accessibility.
  • Plan vendor coordination and remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is REDCap and how is it used?

REDCap is a web-based platform primarily used by academic and clinical institutions to build and manage secure online surveys and databases for research studies and data collection. It provides tools for researchers to design complex data entry forms and import datasets, facilitating clinical research workflows.

What does CWE-73 and CWE-94 mean regarding CVE-2026-90817?

These codes represent weakness classes. CWE-73 refers to improper control of file path names, while CWE-94 refers to improper control of generation of code. In this CVE, they describe a flaw where the system incorrectly processes file-path inputs and routing logic, allowing an attacker to inject and execute their own unauthorized code on the server.

Do I need a valid account to trigger this vulnerability?

No, you do not need to be an authenticated user to trigger the flaw. However, the attack is not automatically indiscriminate. The attacker must possess a valid public survey hash to access the specific survey context required to manipulate the routing and data import functions.

How do I know if my REDCap instance is at risk?

According to Halo Surface Signal, this vulnerability is particularly relevant because REDCap public surveys are designed to be internet-facing for data collection. If your instance hosts public surveys accessible via the internet, it is considered to have a higher potential attack surface.

What is the first step to take if I run REDCap?

Begin by identifying all your deployed REDCap environments and determining which instances host public surveys. Confirm how those surveys are exposed to the internet. Once you have an inventory of your public-facing survey infrastructure, monitor official vendor communications to coordinate necessary updates during a maintenance window.

References