CVE-2026-10072: Interinfo|DreamMaker - Arbitrary File Upload
DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DreamMaker (Interinfo) / Java Composerto a version that resolves this vulnerability.Fixed in 2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10072?
The severity of CVE-2026-10072 is rated high with a score of 8.6.
How do I fix CVE-2026-10072?
To fix CVE-2026-10072, update Interinfo DreamMaker to version Java Composer 2.3 or later.
What type of vulnerability is CVE-2026-10072?
CVE-2026-10072 is classified as an Arbitrary File Upload vulnerability.
Who is affected by CVE-2026-10072?
CVE-2026-10072 affects users of Interinfo DreamMaker.
What are the potential consequences of CVE-2026-10072?
The potential consequences of CVE-2026-10072 include arbitrary code execution through the upload of web shell backdoors.