Junglewise Threat Intelligence

CVE-2026-10075: Interinfo DreamMaker path traversal in Java Composer

CVE-2026-10075 · Severity: medium · CVSS 5.3 · Published 2026-05-29

Technologies: Interinfo DreamMaker Java Composer. Vendors: Interinfo.

Executive brief

Interinfo DreamMaker, a development platform, contains a security flaw that allows unauthorized individuals to view file names on the server. By sending a specially crafted request, an attacker can see what files exist in folders they should not have access to. While this does not allow them to read the content of the files, it exposes sensitive information about the server's structure and installed software.

Technical details

An absolute path traversal vulnerability (CWE-36) exists in Interinfo DreamMaker Java Composer versions 2.2 and earlier. The flaw allows an unauthenticated remote attacker to bypass directory access restrictions by providing absolute file paths in a request. Successful exploitation enables the attacker to enumerate and read file names within arbitrary directories on the host file system. This vulnerability is limited to directory listing (reading file names) rather than full file content disclosure. Users are advised to update to Java Composer version 2.3 or later to remediate the issue.

Affected products

  • Interinfo DreamMaker Java Composer 2.2 and earlier

Timeline

  • 2026-05-29: disclosed: Advisory published by TWCERT/CC
  • 2026-05-29: patched: Fix released in version 2.3

References

Related threats