CRITICAL
9.8 CVE-2026-75031 Published 18 Sept 2026
Interchange Quick Question Admin Remote Code Execution Bug
Worried this affects your website?
A critical remote code execution (RCE) vulnerability has been found in the Interchange project's "quick question" admin feature.
In default installations, arbitrary Perl code can be injected and executed server-side by unauthenticated users.
The Perl code normally runs within a Safe container that limits what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.
Reference: CVE-2026-75031 on NVD
← Back to Security News