Description
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the
“quick question” admin feature. In default installations arbitrary Perl
code can be injected and executed server-side by unauthenticated users.
The Perl code normally runs within a Safe container which limits the
scope of what it can do, unless the non-default AllowGlobal directive is
configured for the catalog being accessed.CTOR]
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The quick question admin feature allows injection of arbitrary Perl code. Normally the code runs inside a Safe container that limits operations, but when the AllowGlobal directive is enabled for a catalog the container is bypassed, giving the injected code full server privileges. This flaw means an attacker can execute any Perl code on the host that runs the Interchange application.

Affected Systems

Deployments of the Interchange e‑commerce platform that expose the quick question admin functionality are vulnerable. The vulnerability is not tied to a specific version in the description, so any installation that includes the unpatched feature is at risk. Administrators should check whether the AllowGlobal setting is enabled for their catalogs and whether the admin function is active.

Risk and Exploitability

The vulnerability is not reported in a KEV catalog and no EPSS score is available, but it permits unauthenticated remote exploitation through the web interface. Attackers can send a crafted request to the admin endpoint and immediately gain code execution on the server. Inferred that the attack vector functions via an unauthenticated HTTP request targeting the admin endpoint. Because the attacker receives full control, the risk remains high despite the absence of an EPSS value.

Generated by OpenCVE AI on September 19, 2026 at 12:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest Interchange release that incorporates the patched quick question admin feature (the fix is referenced by the GitHub commit 65b6ea9d3761dd1fd2071c962819562afa335e4e).
  • If an immediate update cannot be performed, disable the AllowGlobal directive for all catalogs to enforce Safe container limits and prevent injected code from running with full privileges.
  • Alternatively, remove or disable the quick question admin feature entirely to eliminate the injection entry point.

Generated by OpenCVE AI on September 19, 2026 at 12:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Interchange
Interchange interchange
Vendors & Products Interchange
Interchange interchange

Sat, 19 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Critical Remote Code Execution via Unauthenticated Perl Injection in Interchange Quick Question Admin

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Critical Remote Code Execution via Unauthenticated Perl Injection in Interchange Quick Question Admin

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR]
Weaknesses CWE-94
References

Subscriptions

Interchange Interchange
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat-cnalr

Published:

Updated: 2026-09-18T17:27:14.647Z

Reserved: 2026-08-17T15:06:02.303Z

Link: CVE-2026-75031

cve-icon Vulnrichment

Updated: 2026-09-18T17:26:48.005Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:09.043

Modified: 2026-09-18T19:06:08.407

Link: CVE-2026-75031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:10Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')