Sceawere

Vulnerability Detail

CVE-2026-100843UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MONAI Remote Code Execution Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Project-MONAI
Product
MONAI
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-09-27T02:17:22.853Z",
  "pubdate": "2026-09-27T02:17:22.853Z",
  "executiveSummary": "MONAI versions prior to 1.6.0 are susceptible to a critical Remote Code Execution (RCE) vulnerability stemming from the unsafe deserialization of untrusted data.\nThe flaw resides within the algo_from_pickle() function, which utilizes the Python pickle module to reconstruct objects without adequate validation or sanitization.\nBy supplying a maliciously crafted pickle payload, an unauthenticated attacker can achieve arbitrary code execution on the underlying host system under the privileges of the MONAI process.\nThis vulnerability poses a severe risk to confidentiality, integrity, and availability, as it enables full system compromise if an attacker can force the application to deserialize a tainted file.\nThe exploitation process does not require prior authentication, making it a high-priority risk for any infrastructure processing user-supplied data through the affected auto3dseg utilities.",
  "technicalDetails": "The vulnerability is located in monai/auto3dseg/utils.py within the algo_from_pickle() function. The root cause is the reliance on the standard library pickle.loads() method, which is inherently insecure when processing data from non-trusted or untrusted sources.\nIn the Python ecosystem, the pickle module is designed for serializing and de-serializing complex Python objects; however, it is not cryptographically secure against malicious input. The de-serialization process allows for the execution of arbitrary code via the __reduce__ method of a serialized object, which is triggered automatically upon instantiation during the deserialization phase.\nThe attack flow initiates when an attacker gains the ability to provide a serialized file to the vulnerable function. When algo_from_pickle() invokes pickle.loads() on this input, the Python runtime environment reconstructs the object graph. If the payload contains an object with a malicious __reduce__ instruction, the interpreter executes the defined instructions immediately upon deserialization.\nThis payload behavior enables the attacker to spawn a reverse shell, execute system commands, or inject malicious scripts into the host OS. Since the function is likely used in automated pipelines or model loading scenarios within MONAI's auto3dseg module, an attacker could compromise the pipeline by replacing a legitimate configuration file or model checkpoint with a malicious substitute.\nThe vulnerability is present in all MONAI versions before 1.6.0. Exploitation does not require authentication or specific system privileges, provided the application logic permits the loading of arbitrary pickle-serialized assets. Network exposure is dependent on whether the input mechanism for these files is accessible via a web interface, API, or shared storage accessible by the attacker. Post-exploitation, the impact is total host compromise, facilitating lateral movement, data exfiltration, or the installation of persistent backdoors."
}
CVE-2026-100843: MONAI Remote Code Execution Vulnerability (HIGH Severity, CVSS: 7.8) | Sceawere