| TVN ID | TVN-202605004 |
|---|---|
| CVE ID | CVE-2026-10071, CVE-2026-10072, CVE-2026-10073, CVE-2026-10074, CVE-2026-10075 |
| CVSS | 【CVE-2026-10071】 9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 【CVE-2026-10072】 7.2 (High) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 【CVE-2026-10073】 7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 【CVE-2026-10074】 4.9 (Medium) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N 【CVE-2026-10075】 5.3 (Medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| Affected Products | DreamMaker version Java Composer 2.2 and ealier |
| Description | 【CVE-2026-10071(Arbitrary File Upload)】 Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. 【CVE-2026-10072(Arbitrary File Upload)】 Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. 【CVE-2026-10073(Arbitrary File Read)】 Unauthenticated local attackers can exploit Relative Path Traversal to download arbitrary system files. 【CVE-2026-10074(Arbitrary File Read)】 Privileged local attackers can exploit Relative Path Traversal to download arbitrary system files. 【CVE-2026-10075(Path Traversal)】 Unauthenticated remote attackers can read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability. |
| Solution | Update to version Java Composer 2.3 or later |
| Credit | 【CVE-2026-10071, CVE-2026-10072, CVE-2026-10073, CVE-2026-10074】 Linwz(DEVCORE) 【CVE-2026-10075】 Kun Xian Lin (DEVCORE) |
| Public Date | 2026-05-29 |
