A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Project Subscriptions

Vendors Products
Trueconf Subscribe
Trueconf Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5.


Workaround

Perform a full check with anti-virus software that has up-to-date anti-virus databases and software modules.

History

Thu, 20 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Trueconf
Trueconf trueconf Server
CPEs cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
Vendors & Products Trueconf
Trueconf trueconf Server

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-08-20T00:00:00+00:00', 'dueDate': '2026-08-23T00:00:00+00:00'}


Thu, 20 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Script Execution via Undocumented Function in TrueConf Server

Thu, 20 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Script Execution via Undocumented Function in TrueConf Server

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Kaspersky

Published:

Updated: 2026-08-20T17:48:24.155Z

Reserved: 2026-08-10T09:55:18.375Z

Link: CVE-2026-72529

cve-icon Vulnrichment

Updated: 2026-08-19T17:15:42.018Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T17:21:00.990

Modified: 2026-08-20T19:07:48.070

Link: CVE-2026-72529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T13:45:03Z

Weaknesses