CRITICAL 9.8 NVD
CVE-2026-75031
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default instal
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the
“quick question” admin feature. In default installations arbitrary Perl
code can be injected and executed server-side by unauthenticated users.
The Perl code normally runs within a Safe container which limits the
scope of what it can do, unless the non-default AllowGlobal directive is
configured for the catalog being accessed.CTOR]
References
- https://github.com/interchange/interchange/commit/65b6ea9d3761dd1fd2071c962819562afa335e4e
- https://www.interchangecommerce.org/i/dev/news?mv_arg=00071
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-18 via NVD.
Risk Timeline
CVE Disclosed2026-09-18 · -1 days ago
Remediation Resources
vulnfeed aggregates 14649 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.