Posts for: #TrueConf

TrueConf Server Code Injection Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.0Security Advisory

TL;DR 📌

  • TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
  • Highest CVSS: 9.0 (Critical).
  • Listed in CISA KEV (2026-08-20) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-72530.

What it is

CVE-2026-72530 is a code injection vulnerability in TrueConf Server. An attacker with network access to port 4307/TCP can submit a specially crafted script that breaks out of the server’s isolated execution environment and runs arbitrary code on the underlying host.

[]

TrueConf Server Missing Authentication for Critical Function Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-20) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-72529.

What it is

CVE-2026-72529 is a missing authentication for critical function vulnerability in TrueConf Server. A critical function is reachable over the network on port 4307/TCP without any authentication check.

[]