Remote Code Execution Vulnerability in MONAI Product from Project MONAI
CVE-2026-100840

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100840?

The MONAI framework, up to version 1.6.0, is susceptible to a remote code execution vulnerability introduced through its bundle configuration engine. This flaw allows malicious actors to craft bundles that can execute arbitrary code by leveraging unresolved target values, bypassing security measures such as an allow list. The vulnerability arises as the system improperly processes $ expressions through Python's eval() function when the bundle is loaded or executed. Users are advised to update to the latest version and review security practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

MONAI 0 <= 1.6.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ochk0
.