CVE-2026-75031

EUVD-2026-82993
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the 
“quick question” admin feature. In default installations arbitrary Perl 
code can be injected and executed server-side by unauthenticated users. 
The Perl code normally runs within a Safe container which limits the 
scope of what it can do, unless the non-default AllowGlobal directive is
 configured for the catalog being accessed.CTOR]
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H