Skip to main content
CRITICAL

CVE-2026-75031

CVSS v3

9.8

CRITICAL

EPSS Score

0.7 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR]

Technical details

Published
2026-09-18
Last Modified
2026-09-18

Frequently asked questions

What is CVE-2026-75031?

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR]

Is CVE-2026-75031 actively exploited?

Active exploitation of CVE-2026-75031 has not been confirmed. Its EPSS score was 0.7% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-75031?

CVE-2026-75031 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2026-75031 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key