External risk intelligence

Interchange Quick Question Admin RCE Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-75031

The vulnerability resides in an administrative feature of the Interchange e-commerce platform. As e-commerce platforms are typically deployed as internet-facing web applications to facilitate customer transactions and catalog management, an administrative interface or feature within such a product is commonly reachable or exposed in standard web-accessible deployments.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the interchange project, specifically within an administrative feature. This issue could allow unauthenticated users to execute arbitrary code on servers, potentially leading to significant compromise. The primary concern is to determine if this specific administrative feature is enabled and accessible in your environment.

  • Unauthenticated users can run unauthorized code.
  • Critical administrative feature could be exposed externally.
  • Confirm exposure and relevance to your systems.

Attack Path

How an attacker could exploit the issue

Attackers can reach and trigger this vulnerability by sending specially crafted requests to the "quick question" feature of the interchange project. This feature is accessible by unauthenticated users over the network. If the non-default `AllowGlobal` directive is enabled for the accessed catalog, attackers can inject and execute arbitrary Perl code on the server, potentially leading to critical impacts.

  • Unauthenticated network access required.
  • Injects Perl code into a specific feature.
  • Remote code execution leading to server compromise.

Live Threat

Current exploitation, exposure, and threat context

In default installations of the interchange/interchange project, unauthenticated users could inject and execute arbitrary Perl code on the server through the "quick question" admin feature. This execution could occur if the non-default `AllowGlobal` directive is enabled for the accessed catalog, potentially leading to a compromise of server resources.

  • Server-side code execution.
  • Exploited via "quick question" feature.
  • Unauthenticated code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical remote code execution vulnerability in the "quick question" admin feature of the interchange/interchange project requires immediate attention. The default installation allows unauthenticated users to inject and execute arbitrary Perl code server-side, especially when the non-default `AllowGlobal` directive is enabled. The first practical step is to identify all instances of this software, determine their exposure and business criticality, and locate the accountable owner before planning remediation.

  • Application owners should triage and assess risk.
  • Verify Perl code execution with `AllowGlobal` enabled.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the interchange project?

Interchange is an open-source e-commerce platform used to build and manage online stores. It handles product catalogs, shopping carts, and administrative tasks required for running retail web applications.

What does CVE-2026-75031 mean for my server?

This vulnerability is a Code Injection flaw, categorized as CWE-94. It means an unauthorized person can send malicious Perl code to the 'quick question' admin feature, which the server might then execute as if it were a legitimate internal command.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted request over the network to the 'quick question' feature. Importantly, simply having the feature is not enough; the vulnerability typically requires the non-default 'AllowGlobal' setting to be enabled to escape standard security containers.

Do I need to worry if my interchange instance is internal?

Halo Surface Signal indicates that because this is an e-commerce platform, these installations are frequently internet-facing to manage transactions. If your specific instance is reachable from the public internet, the risk is significantly higher than for a strictly internal, isolated system.

What should I do first to address this issue?

Begin by locating all running instances of interchange in your environment. Once identified, consult with the application owners to check your configuration files for the 'AllowGlobal' directive and prioritize those installations that are accessible via the internet.

References