CVE-2026-72530
Analyzed
Analyzed - Analysis Complete
Remote Code Execution in TrueConf Server
Vulnerability report for CVE-2026-72530, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-19
Last updated on: 2026-08-21
Assigner: Kaspersky Labs
Description
Description
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| trueconf | trueconf_server | to 5.3.9.10013 (exc) |
| trueconf | trueconf_server | From 5.4.0.12689 (inc) to 5.4.9.10072 (exc) |
| trueconf | trueconf_server | From 5.5.0.13826 (inc) to 5.5.5.10010 (exc) |
| trueconf | trueconf_server | to 5.3.9.10015 (exc) |
| trueconf | trueconf_server | From 5.4.0.12700 (inc) to 5.4.9.10019 (exc) |
| trueconf | trueconf_server | From 5.5.0.13828 (inc) to 5.5.5.10009 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-94 | The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. |