CVE-2026-10071: Interinfo|DreamMaker - Arbitrary File Upload
DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DreamMaker (Interinfo)to a version that resolves this vulnerability.Fixed in Java Composer 2.3 or later
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10071?
The severity of CVE-2026-10071 is rated as critical with a score of 9.3.
What are the impacts of CVE-2026-10071?
CVE-2026-10071 allows unauthenticated remote attackers to upload and execute web shell backdoors, enabling arbitrary code execution on the server.
How do I fix CVE-2026-10071?
To fix CVE-2026-10071, update to version Java Composer 2.3 or later.
Which software is affected by CVE-2026-10071?
Interinfo DreamMaker is the software affected by CVE-2026-10071.
What type of vulnerability is CVE-2026-10071 classified as?
CVE-2026-10071 is classified as a Malicious File Upload vulnerability.