OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-75031

CRITICAL · CVSS 9.8 EPSS 0.71% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability exists in the "quick question" admin feature of the interchange project, allowing unauthenticated users to inject and execute arbitrary Perl code on the server in default installations. This poses a critical remote code execution risk, particularly if the AllowGlobal directive is enabled, which can expand the attacker's capabilities. Organizations using the interchange project should prioritize addressing this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75031
Severity
CRITICAL
CVSS
9.8
EPSS
0.71%

Original NVD Description

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR]