CVE-2026-24728
Severity CVSS v4.0:
CRITICAL
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
30/01/2026
Last modified:
30/01/2026
Description
A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



