Description
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Published: 2026-08-19
Score: 9.3 Critical
EPSS: 1.6% Low
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with access to the TrueConf Server port 4307/TCP can trigger an undocumented function that lets them execute arbitrary scripts. Because the function lacks authentication checks, the attacker can run any commands on the host, potentially gaining full control and compromising confidentiality, integrity, and availability of the server.

Affected Systems

TrueConf Server versions 5.3.x to 5.3.9, 5.4.x to 5.4.9, 5.5.x to 5.5.5, and all earlier releases are affected. The product is deployed by TrueConf under the TrueConf Server banner.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, and the EPSS score is less than 1%, indicating a very low exploitation probability, although the vulnerability is listed in the CISA KEV catalog. The lack of authentication allows remote exploitation from any network host that can reach port 4307, so the risk is high for exposed servers. The attack requires only network connectivity and no special privileges, making it readily exploitable if the server is reachable.

Generated by OpenCVE AI on August 20, 2026 at 21:54 UTC.

Remediation

Vendor Solution

Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5.


Vendor Workaround

Perform a full check with anti-virus software that has up-to-date anti-virus databases and software modules.


OpenCVE Recommended Actions

  • Upgrade TrueConf Server to version 5.3.9, 5.4.9, or 5.5.5 to obtain the vendor‑supplied fix that removes the unauthenticated function.
  • Run a full audit with up‑to‑date anti‑virus software and look for indicators of compromise.
  • If compromised accounts are suspected, reset all passwords and contact Kaspersky ICSS CERT for incident response guidance.

Generated by OpenCVE AI on August 20, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Trueconf trueconf
Vendors & Products Trueconf trueconf

Thu, 20 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title TrueConf Server Remote Unauthorized Function Enables Arbitrary Script Execution via Port 4307

Thu, 20 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Trueconf
Trueconf trueconf Server
CPEs cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
Vendors & Products Trueconf
Trueconf trueconf Server

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-08-20T00:00:00+00:00', 'dueDate': '2026-08-23T00:00:00+00:00'}


Thu, 20 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Script Execution via Undocumented Function in TrueConf Server

Thu, 20 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Script Execution via Undocumented Function in TrueConf Server

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Trueconf Trueconf Trueconf Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Kaspersky

Published:

Updated: 2026-08-21T03:55:16.895Z

Reserved: 2026-08-10T09:55:18.375Z

Link: CVE-2026-72529

cve-icon Vulnrichment

Updated: 2026-08-19T17:15:42.018Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T17:21:00.990

Modified: 2026-08-21T04:18:15.753

Link: CVE-2026-72529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function