A security flaw has been identified in TrueConf Server, a service some users run on their hosted accounts. This is a code injection vulnerability, a type of issue that allows unauthorized parties to insert and run harmful, unapproved code on a system.
To exploit this flaw, an attacker would need unauthorized network access to port 4307/TCP, the specific communication port used by TrueConf Server. If they can reach this port, they can send a specially crafted script to break out of the service’s built-in isolated security environment.
If successful, the attacker can run any code they want on the host server running TrueConf Server. This grants them unauthorized control over the service and its underlying server, which could put your hosted data and account activity at risk.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530