CRITICAL 9.8 CVE-2026-75031 Published 18 Sept 2026

Interchange Quick Question Admin Remote Code Execution Bug

Worried this affects your website?

A critical remote code execution (RCE) vulnerability has been found in the Interchange project's "quick question" admin feature.

In default installations, arbitrary Perl code can be injected and executed server-side by unauthenticated users.

The Perl code normally runs within a Safe container that limits what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.

Reference: CVE-2026-75031 on NVD

← Back to Security News