TrueConf Server: TrueConf Server Code Injection Vulnerability

  • Saturday, 22nd August, 2026
  • 16:04pm

A security flaw has been found in TrueConf Server that is a code injection vulnerability, meaning it lets malicious, specially crafted input run unauthorized commands on the affected system.

If an unauthorized remote attacker can access your TrueConf Server instance via the 4307/TCP network port, they could use a specially built script to break out of the isolated, restricted environment that TrueConf Server is designed to operate in. This would let them run arbitrary code directly on the underlying host server that runs your TrueConf setup.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530

« Back