A code injection vulnerability has been identified in TrueConf Server, a service some customers may run on their hosting accounts. This flaw poses a security risk for anyone using this software as part of their hosted setup.
The vulnerability can be exploited by an unauthorized remote attacker who has network access to your server's 4307/TCP port. By sending a specially crafted script, the attacker can break out of the isolated, restricted environment that TrueConf Server is designed to operate within, and execute arbitrary code on the underlying host system that supports your hosting account.
If successfully exploited, the attacker would be able to run any commands or code they choose on your hosting system, which could compromise the security of your hosted websites, services, and stored data.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530