TrueConf Server Missing Authentication for Critical Function Vulnerability
TL;DR 📌
- A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
- Highest CVSS: 9.8 (Critical).
- Listed in CISA KEV (2026-08-20) — this is being exploited in the wild.
- Fixed in
5.3.9.10013,5.3.9.10015,5.4.9.10019,5.4.9.10072— upgrade to this release or later. - CVEs: CVE-2026-72529.
What it is
CVE-2026-72529 is a missing authentication vulnerability in TrueConf Server. The affected component exposes an undocumented function on port 4307/TCP that can be called without any credentials, and calling it allows arbitrary script execution.
The access path is straightforward: an attacker only needs network reachability to port 4307/TCP on the target server. No authentication, no user interaction, and no prior access to the environment is required (AV:N/AC:L/PR:N/UI:N in the CVSS vector). The CVSS score of 9.8 reflects full compromise of confidentiality, integrity, and availability once the flaw is triggered.
This affects TrueConf server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-08-20, meaning it is known to be exploited.
What to do
- Identify any TrueConf Server instances in the versions ranges 5.3.X–5.3.9, 5.4.X–5.4.9, 5.5.X–5.5.5, or earlier.
- Upgrade to one of the fixed builds: 5.3.9.10013, 5.3.9.10015, 5.4.9.10019, 5.4.9.10072, 5.5.5.10009, or 5.5.5.10010, depending on your current branch.
- Until patched, restrict network access to port 4307/TCP to only trusted management hosts, or block it entirely at the perimeter if it is not required for normal operation.
- Given this is in CISA KEV, treat patching as urgent and prioritise it over routine maintenance windows.
- After upgrading, confirm the running build number matches one of the fixed releases above rather than relying on the major.minor version alone, since the vulnerable ranges extend up to specific patch levels within each branch.
For leadership 🧭
Executive summary. TrueConf Server instances on branches up to 5.3.9, 5.4.9 or 5.5.5 can be fully taken over by anyone with network access to port 4307/TCP, with no credentials needed, and the flaw is already being exploited in the wild. This should be treated as an immediate patching priority rather than scheduled into routine maintenance.
Why it matters:
- Port 4307/TCP exposes an undocumented function that requires no authentication, so any attacker with network reachability can trigger arbitrary script execution on the server.
- The CVSS 3.1 score of 9.8 reflects total loss of confidentiality, integrity and availability once the function is called.
- The flaw is listed in CISA’s Known Exploited Vulnerabilities catalogue, confirming active exploitation rather than a theoretical risk.
- Every TrueConf Server branch from 5.3.X through 5.5.5, and earlier releases, is affected until upgraded to a specific fixed build number.
Now / Next / Later:
- Now: Check which TrueConf Server builds are running in your environment and whether port 4307/TCP is reachable from untrusted networks; if it is, restrict or block access to trusted management hosts immediately.
- Next: Upgrade affected servers to one of the fixed builds (5.3.9.10013, 5.3.9.10015, 5.4.9.10019, 5.4.9.10072, 5.5.5.10009 or 5.5.5.10010) matching your current branch, verifying the exact build number rather than just the major.minor version.
- Later: Add TrueConf Server to your asset inventory with tracked build numbers and review firewall rules so that management-plane ports like 4307/TCP are never reachable beyond a defined set of trusted hosts by default.