CVE-2026-72530: Code Injection
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TrueConf serverto a version that resolves this vulnerability.Fixed in 5.3.9 - Upgrade
Upgrade
TrueConf serverto a version that resolves this vulnerability.Fixed in 5.4.9 - Upgrade
Upgrade
TrueConf serverto a version that resolves this vulnerability.Fixed in 5.5.5
Event History
Frequently Asked Questions
Which systems are exposed to remote exploitation?
TrueConf Server instances that are reachable over TCP port 4307 and run versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, or earlier are exposed.
Does exploitation require an authenticated account or user interaction?
No. The vulnerability is described as exploitable by an unauthorized remote attacker, with no privileges or user interaction required.
What level of access could successful exploitation provide?
A specially crafted script can allow an attacker to escape the isolated environment and execute arbitrary code on the host system. The reported impact includes high confidentiality, integrity, and availability impact.