← Back to search

CVE-2026-75031

9.8 CRITICALpublic exploit available

Published 2026-09-18 · Updated 2026-09-18

AI risk analysis

Summary
This vulnerability allows unauthenticated users to execute arbitrary Perl code server-side through the 'quick question' admin feature, leading to remote code execution.
Exploitability
Exploitation is relatively easy as it requires no authentication, but depends on the AllowGlobal directive being misconfigured.
Blast radius
If exploited, this could lead to complete server compromise, allowing attackers to execute arbitrary code and potentially gain full control over the system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the 'quick question' admin feature or ensure the AllowGlobal directive is not configured for the catalog being accessed.
rceperladminunauthweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR]

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.