A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5.


Workaround

Perform a full check with anti-virus software that has up-to-date anti-virus databases and software modules.

History

Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Trueconf
Trueconf server
Vendors & Products Trueconf
Trueconf server

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Kaspersky

Published:

Updated: 2026-08-19T17:16:31.110Z

Reserved: 2026-08-10T09:55:18.375Z

Link: CVE-2026-72530

cve-icon Vulnrichment

Updated: 2026-08-19T17:16:19.874Z

cve-icon NVD

Status : Received

Published: 2026-08-19T17:21:01.130

Modified: 2026-08-19T18:17:24.933

Link: CVE-2026-72530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T19:00:04Z

Weaknesses