CVE-2026-100846 HIGH

CVE-2026-100846: MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization

Vendor Project-Monai
Product MONAI
Weakness CWE-502 · Unsafe deserialization
Published September 27, 2026
Last update September 30, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserialization, resulting in arbitrary code execution in the context of the application.

Key dates

02Disclosure timeline

September 27, 2026 CVE published
September 30, 2026 Record updated

Related vulnerabilities

04Related CVE