CVE-2026-24728: Internet Information Co., Ltd Dreammaker
Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication.
Affected products
- Internet Information Co., Ltd Dreammaker
Published 2026-01-30. Last modified 2026-06-17.