CVE-2026-24728: Internet Information Co., Ltd Dreammaker

Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication.

Affected products

Published 2026-01-30. Last modified 2026-06-17.