TrueConf Server: TrueConf Server Code Injection Vulnerability

  • Friday, 21st August, 2026
  • 10:06am

A code injection security flaw has been found in TrueConf Server, a video conferencing tool that some users may run on their hosting accounts. This vulnerability could let an unauthorized remote attacker who is able to reach the server's 4307/TCP network port use a specially crafted script to break out of the tool's isolated protected environment, and run any code they want directly on the host system that powers your hosted services. If successfully exploited, this could give the attacker unauthorized access to your hosting environment, letting them steal sensitive data, disrupt your website or other services you run, or use your server for additional malicious activity.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530

« Back