CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-20. EPSS: 1.5% chance of exploitation in the next 30 days.
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Affected products
- TrueConf TrueConf Server: before 5.3.9.10013 (fixed in 5.3.9.10013); before 5.3.9.10015 (fixed in 5.3.9.10015); from 5.4.0.12689, before 5.4.9.10072 (fixed in 5.4.9.10072); from 5.4.0.12700, before 5.4.9.10019 (fixed in 5.4.9.10019); from 5.5.0.13826, before 5.5.5.10010 (fixed in 5.5.5.10010); from 5.5.0.13828, before 5.5.5.10009 (fixed in 5.5.5.10009)
Published 2026-08-19. Last modified 2026-08-21.