TrueConf Server Code Injection Vulnerability
TL;DR 📌
- A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
- Highest CVSS: 9.0 (Critical).
- Listed in CISA KEV (2026-08-20) — this is being exploited in the wild.
- Fixed in
5.3.9.10013,5.3.9.10015,5.4.9.10019,5.4.9.10072— upgrade to this release or later. - CVEs: CVE-2026-72530.
What it is
CVE-2026-72530 is a code injection vulnerability in TrueConf Server, reachable by an unauthenticated remote attacker over port 4307/TCP. The flaw allows a specially crafted script to break out of an isolated environment on the server and execute arbitrary code on the host.
No authentication or user interaction is required to reach the vulnerable component (PR:N, UI:N, AV:N in the CVSS vector), though the attack complexity is rated high (AC:H). The scope change (S:C) indicates the sandbox escape allows the attacker to affect resources beyond the originally vulnerable component, consistent with the description of breaking out of an isolated environment to reach the host.
Affected versions are TrueConf Server 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier. The impact covers confidentiality, integrity and availability in full (C:H/I:H/A:H), meaning successful exploitation gives arbitrary code execution on the underlying host, not just within whatever sandbox is meant to contain scripts.
This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-08-20.
What to do
- Restrict or firewall access to port 4307/TCP on TrueConf Server deployments; this port should not be exposed to untrusted networks.
- Upgrade to a fixed build. NVD lists fixed versions 5.3.9.10013, 5.3.9.10015, 5.4.9.10019, 5.4.9.10072, 5.5.5.10009 and 5.5.5.10010 — apply the one matching your current branch.
- Given the KEV listing, treat patching as urgent and prioritise internet-facing or otherwise network-reachable TrueConf servers.
- Review TrueConf server logs for anomalous script activity or unexpected process execution around the affected service, particularly on hosts where port 4307/TCP was previously reachable from untrusted segments.
For leadership 🧭
Executive summary. TrueConf Server instances exposing port 4307/TCP can be taken over completely by a remote attacker with no login required, and this is already listed as exploited in the wild. Given the KEV listing, this needs urgent action this week, not at the next routine patch cycle.
Why it matters:
- The vulnerable path is port 4307/TCP on TrueConf Server, a service that does not require authentication or user interaction to reach.
- Successful exploitation breaks out of the intended sandbox for scripts and grants full code execution on the host, not just within the isolated environment — full confidentiality, integrity and availability impact.
- Versions 5.3.X up to 5.3.9, 5.4.X up to 5.4.9, 5.5.X up to 5.5.5, and earlier are all affected, covering a wide span of deployed installs.
- CISA added this to its Known Exploited Vulnerabilities catalogue on 2026-08-20, meaning attackers are already using this technique against real targets.
Now / Next / Later:
- Now: Firewall or otherwise restrict access to port 4307/TCP on every TrueConf Server so it is not reachable from untrusted networks, and identify which instances currently expose it.
- Next: Upgrade each TrueConf Server to the fixed build matching its branch — 5.3.9.10013 or 5.3.9.10015, 5.4.9.10019 or 5.4.9.10072, or 5.5.5.10009 or 5.5.5.10010.
- Later: Add TrueConf Server to a regular exposure review so ports like 4307/TCP are checked against network policy whenever new instances are deployed, and review server logs now for anomalous script or process activity predating the fix.