Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-75031: Interchange lets unauthenticated users run code via quick question
CVE-2026-75031 · published 22 days ago
Summary
The Interchange web‑store software’s admin “quick question” feature can run arbitrary Perl code on the server. If the default settings are used, anyone on the internet could inject code and have it executed, potentially taking control of the system. Apply the recommended configuration changes or update to a patched version to stop this behavior.
What to do
- Update interchange interchange to version * or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| interchange | interchange | < * |
Original advisory text
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the
“quick question” admin feature. In default installations arbitrary Perl
code can be i...
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the
“quick question” admin feature. In default installations arbitrary Perl
code can be injected and executed server-side by unauthenticated users.
The Perl code normally runs within a Safe container which limits the
scope of what it can do, unless the non-default AllowGlobal directive is
configured for the catalog being accessed.CTOR]
“quick question” admin feature. In default installations arbitrary Perl
code can be injected and executed server-side by unauthenticated users.
The Perl code normally runs within a Safe container which limits the
scope of what it can do, unless the non-default AllowGlobal directive is
configured for the catalog being accessed.CTOR]
References
- https://www.interchangecommerce.org/i/dev/news?mv_arg=00071
- https://github.com/interchange/interchange/commit/65b6ea9d3761dd1fd2071c96281956...
- https://github.com/interchange/interchange/ URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75031... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-75031 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-94Code Injection
Timeline
Published18 Sep 2026
Updated7 Oct 2026
First seen18 Sep 2026
Track software like this
Free during beta