CVE-2026-24729: Internet Information Co., Ltd Dreammaker

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.

Affected products

Published 2026-01-30. Last modified 2026-06-17.