CVE-2026-10075: Interinfo|DreamMaker - Path Traversal
DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Java Composer (DreamMaker by Interinfo)to a version that resolves this vulnerability.Fixed in 2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10075?
CVE-2026-10075 has a medium severity rating of 5.3.
What type of vulnerability is described in CVE-2026-10075?
CVE-2026-10075 describes a Path Traversal vulnerability in the Interinfo DreamMaker software.
How can I fix CVE-2026-10075?
To fix CVE-2026-10075, update to Java Composer version 2.3 or later.
Who is affected by CVE-2026-10075?
CVE-2026-10075 affects users of Interinfo DreamMaker, particularly vulnerable versions prior to the update.
What can attackers do by exploiting CVE-2026-10075?
By exploiting CVE-2026-10075, unauthenticated remote attackers can read file names from arbitrary paths.