Junglewise Threat Intelligence

CVE-2026-10074: Interinfo DreamMaker arbitrary file read via relative path traversal

CVE-2026-10074 · Severity: medium · CVSS 4.9 · Published 2026-05-29

Technologies: Interinfo DreamMaker Java Composer. Vendors: Interinfo.

Executive brief

Interinfo DreamMaker, a development platform, contains a security flaw that allows authorized users to access sensitive system files. An attacker with existing high-level privileges on the local system can bypass folder restrictions to download files they should not be able to see. This could lead to the exposure of configuration data or other sensitive information stored on the server.

Technical details

A relative path traversal vulnerability (CWE-23) exists in Interinfo DreamMaker Java Composer version 2.2 and earlier. The flaw allows a local attacker with high privileges (PR:H) to bypass directory restrictions and read arbitrary files on the host system. By supplying specially crafted input containing path traversal sequences (e.g., ../), the attacker can download sensitive system files. The vulnerability is resolved in Java Composer version 2.3. Note: While the description mentions 'local' attackers, the CVSS vector provided by the CNA (AV:N) suggests a network-reachable component is involved.

Affected products

  • Interinfo DreamMaker Java Composer 2.2 and earlier

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory
  • 2026-05-29: patched: Fixed in Java Composer 2.3

References

Related threats