Junglewise Threat Intelligence

CVE-2026-10071: Interinfo DreamMaker arbitrary file upload in Java Composer

CVE-2026-10071 · Severity: critical · CVSS 9.8 · Published 2026-05-29

Technologies: Interinfo DreamMaker Java Composer. Vendors: Interinfo.

Executive brief

Interinfo DreamMaker, a development platform, contains a critical security flaw that allows unauthorized individuals to upload malicious files to the server. By exploiting this vulnerability, an attacker can gain full control over the system, potentially leading to the theft of sensitive data, service disruption, or the installation of ransomware. This issue can be triggered remotely without any valid login credentials.

Technical details

An arbitrary file upload vulnerability (CWE-434) exists in Interinfo DreamMaker Java Composer versions 2.2 and earlier. The flaw allows an unauthenticated remote attacker to upload files with dangerous extensions to the server. By uploading a web shell or similar backdoor, the attacker can achieve remote code execution (RCE) with the privileges of the web service. The vulnerability is exploitable over the network without user interaction. Users are advised to update to Java Composer version 2.3 or later to mitigate this risk.

Affected products

  • Interinfo DreamMaker Java Composer 2.2 and earlier

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory
  • 2026-05-29: patched: Update to Java Composer 2.3 or later

References

Related threats