CVE-2026-72529: Critical severity TrueConf Server vulnerability
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TrueConf serverto a version that resolves this vulnerability.Fixed in 5.3.9 - Upgrade
Upgrade
TrueConf serverto a version that resolves this vulnerability.Fixed in 5.4.9 - Upgrade
Upgrade
TrueConf serverto a version that resolves this vulnerability.Fixed in 5.5.5
Event History
Frequently Asked Questions
Which systems are exposed to exploitation?
TrueConf Server instances in the listed affected version ranges are exposed if an attacker can reach TCP port 4307 over the network. Exploitation does not require authentication or user interaction.
What level of access can an attacker obtain?
An unauthenticated remote attacker can execute an arbitrary script by invoking an undocumented function. The vulnerability is rated critical with high impact on confidentiality, integrity, and availability.