Arbitrary File Read Vulnerability in DreamMaker by Interinfo
CVE-2026-10074

6.9MEDIUM

Key Information:

Vendor

Interinfo

Vendor
CVE Published:
29 May 2026

What is CVE-2026-10074?

DreamMaker, a product developed by Interinfo, is susceptible to an Arbitrary File Read vulnerability due to improper validation of file path inputs. This issue allows privileged local attackers to exploit Relative Path Traversal, facilitating unauthorized access to download various system files. Proper security measures and updates are crucial to mitigate potential exploitation.

Affected Version(s)

DreamMaker 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.