A code injection security flaw has been identified in TrueConf Server, a communication tool that some users run on their hosted servers. This type of vulnerability allows unauthorized parties to insert malicious, unapproved commands into the affected system.
The flaw can be exploited by any remote attacker who has network access to port 4307/TCP, the specific port TrueConf Server uses for data transmission. By sending a specially crafted script, an attacker can break out of the isolated, restricted environment that TrueConf Server is designed to run in, and execute arbitrary code directly on the server’s host operating system.
If successfully exploited, this could allow an attacker to take control of your server. This creates risks including stolen sensitive data, disrupted website or service operation, or your server being used for harmful activities without your knowledge.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530