CVE-2026-24728: Interinfo DreamMaker - Missing Authentication for Critical Function
A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24728?
CVE-2026-24728 is rated as a critical severity vulnerability due to its potential for allowing unauthorized administrative access.
How do I fix CVE-2026-24728?
To fix CVE-2026-24728, upgrade to Interinfo DreamMaker version 2025/10/22 or later where the vulnerability is patched.
What systems are affected by CVE-2026-24728?
CVE-2026-24728 affects Interinfo DreamMaker versions prior to 2025/10/22.
Can CVE-2026-24728 be exploited remotely?
Yes, CVE-2026-24728 can be exploited remotely by attackers to gain unauthorized access to administrative functions.
What risks does CVE-2026-24728 pose?
CVE-2026-24728 poses risks of unauthorized access, data manipulation, and potential compromise of sensitive information.