A code injection vulnerability has been found in TrueConf Server. This flaw lets an unauthorized remote attacker with network access to the server's port 4307 send a specially crafted script to break out of the server's isolated security environment. If the flaw is exploited, the attacker can run any code they want on the server's host system. If you run TrueConf Server on your hosting account, this vulnerability could allow an unauthorized person to access your website and account data, disrupt your services, or take full control of your server.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530