CVE-2026-24729: Interinfo DreamMaker - Unrestricted Upload of File with Dangerous Type
Published Jan 30, 2026
·Updated
An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.
Affected Software
1 affected component
Interinfo DreamMaker<2025/10/22
Event History
Jan 30, 2026
CVE Published
via MITRE·03:50 AM
Data Sourced
via MITRE·03:50 AM
DescriptionWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeakness
Jul 24, 58068
Event
via FIRST·10:11 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-24729?
CVE-2026-24729 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2026-24729?
To mitigate CVE-2026-24729, update Interinfo DreamMaker to version 2025/10/22 or later.
3
What types of files can be uploaded in CVE-2026-24729?
CVE-2026-24729 allows unrestricted uploads of files with dangerous types, which can include executable scripts.
4
Who is affected by CVE-2026-24729?
Users of Interinfo DreamMaker versions prior to 2025/10/22 are affected by CVE-2026-24729.
5
What impact does CVE-2026-24729 have on system security?
CVE-2026-24729 can lead to arbitrary code execution, compromising the entire system's security.