A code injection vulnerability has been identified in TrueConf Server, a service some hosting clients run on their accounts. This flaw allows outside actors to send malicious, specially designed input to the server to manipulate its internal operations.
An unauthorized remote attacker with network access to your server’s 4307/TCP port could exploit this issue using a custom script to break out of the isolated, restricted environment that TrueConf Server is built to run in. If the exploit is successful, the attacker can execute any arbitrary code they choose directly on your server’s main host system.
This flaw poses a risk to anyone using TrueConf Server on their hosting, as successful exploitation could let attackers gain control of your server, access your website and stored data, or use your server resources for malicious activity.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530