A security flaw has been identified in TrueConf Server. This is a code injection vulnerability, a type of issue that lets unauthorized people run custom, unapproved code on systems running the affected software. To exploit this flaw, an attacker would need network access to port 4307/TCP on the system hosting TrueConf Server. They can send a specially designed script to break out of the isolated, restricted environment that is intended to keep the service separate from the rest of your server, allowing them to run any code they want directly on your host system. If you use TrueConf Server as part of your hosting setup, this vulnerability could let attackers gain full control of your server, access sensitive data stored on it, or disrupt any websites or other services you run on that system.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530