Junglewise Threat Intelligence

CVE-2026-10072: Interinfo DreamMaker arbitrary file upload in Java Composer

CVE-2026-10072 · Severity: high · CVSS 7.2 · Published 2026-05-29

Technologies: Interinfo DreamMaker Java Composer. Vendors: Interinfo.

Executive brief

Interinfo DreamMaker, a development platform, contains a security flaw that allows authorized users with high-level privileges to upload malicious files. An attacker with administrative access could use this to install a web backdoor, granting them full control over the server. This could lead to the theft of sensitive data, complete service disruption, or further attacks on the internal network.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in Interinfo DreamMaker Java Composer version 2.2 and earlier. The flaw allows a remote attacker with high privileges (PR:H) to upload executable files, such as web shells, to the server. Because the application fails to properly validate or sanitize the uploaded file types, these files can be executed in the context of the web server, leading to full arbitrary code execution (RCE). Users are advised to update to Java Composer version 2.3 or later to remediate this issue.

Affected products

  • Interinfo DreamMaker Java Composer 2.2 and earlier

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory
  • 2026-05-29: patched: Fixed in Java Composer 2.3

References

Related threats