Remote Code Execution Vulnerability in Interchange by Interchange Commerce
CVE-2026-75031

Currently unrated

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-75031?

A remote code execution vulnerability exists within the 'quick question' admin feature of the Interchange platform. This flaw allows unauthorized users to inject and execute arbitrary Perl code on the server in default installations. Although the Perl code execution typically operates within a restricted Safe container, the impact can be significantly exacerbated if the AllowGlobal directive is improperly configured for the catalog in use, enabling broader access to system resources.

Affected Version(s)

Interchange 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.