CVE-2026-10075: Interinfo Dreammaker

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.

Affected products

Published 2026-05-29. Last modified 2026-07-21.