CVE-2026-72529 PUBLISHED

Assigner: Kaspersky
Reserved: 10.08.2026 Published: 19.08.2026 Updated: 20.08.2026

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor TrueConf
Product TrueConf Server
Versions Default: unaffected
  • affected from * to 5.3 (excl.)
  • affected from 5.3 to 5.3.9 (excl.)
  • affected from 5.4 to 5.4.9 (excl.)
  • affected from 5.5 to 5.5.5 (excl.)

Workarounds

Conduct a scan for indicators of compromise. In the event of detecting indicators of compromise, change passwords for accounts that may have been compromised and contact Kaspersky ICS CERT at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident.

Solutions

Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5.

Credits

  • Vyacheslav Kopeytsev from Kaspersky ICS CERT finder

References

Problem Types

  • CWE-306: Missing Authentication for Critical Function CWE