SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85540

HIGH · CVSS 8.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

DreamMaker by Interinfo is vulnerable to a SQL Injection flaw that allows authenticated remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized access, modification, or deletion of database contents. Organizations using this software should prioritize patching this vulnerability due to its high severity and the significant risk it poses to data integrity and confidentiality. Immediate action is recommended for any entity that relies on DreamMaker for database management.

CVE
CVE-2026-85540
Severity
HIGH
CVSS
8.8
EPSS
0.31%

Original NVD Description

DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.