CVE-2026-72530 PUBLISHED

Assigner: Kaspersky
Reserved: 10.08.2026 Published: 19.08.2026 Updated: 20.08.2026

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.5

Product Status

Vendor TrueConf
Product TrueConf Server
Versions Default: unaffected
  • affected from * to 5.3 (excl.)
  • affected from 5.3 to 5.3.9 (excl.)
  • affected from 5.4 to 5.4.9 (excl.)
  • affected from 5.5 to 5.5.5 (excl.)

Workarounds

Conduct a scan for indicators of compromise. In the event of detecting indicators of compromise, change passwords for accounts that may have been compromised and contact Kaspersky ICS CERT at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident.

Solutions

Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5.

Credits

  • Vyacheslav Kopeytsev from Kaspersky ICS CERT finder

References

Problem Types

  • CWE-94: Code Injection CWE