Description
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the
“quick question” admin feature. In default installations arbitrary Perl
code can be injected and executed server-side by unauthenticated users.
The Perl code normally runs within a Safe container which limits the
scope of what it can do, unless the non-default AllowGlobal directive is
configured for the catalog being accessed.CTOR]
“quick question” admin feature. In default installations arbitrary Perl
code can be injected and executed server-side by unauthenticated users.
The Perl code normally runs within a Safe container which limits the
scope of what it can do, unless the non-default AllowGlobal directive is
configured for the catalog being accessed.CTOR]
Published:
2026-09-18
Score:
n/a
EPSS:
n/a
KEV:
No
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 18 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR] | |
| Weaknesses | CWE-94 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: redhat-cnalr
Published:
Updated: 2026-09-18T17:27:14.647Z
Reserved: 2026-08-17T15:06:02.303Z
Link: CVE-2026-75031
No data.
Status : Received
Published: 2026-09-18T16:17:09.043
Modified: 2026-09-18T18:17:12.730
Link: CVE-2026-75031
No data.
OpenCVE Enrichment
No data.
Weaknesses