CVE-2026-72529
EUVD-2026-6258719.08.2026, 17:21
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| trueconf | trueconf_server | 𝑥 < 5.3.9.10013 |
| trueconf | trueconf_server | 𝑥 < 5.3.9.10015 |
| trueconf | trueconf_server | 5.4.0.12689 ≤ 𝑥 < 5.4.9.10072 |
| trueconf | trueconf_server | 5.4.0.12700 ≤ 𝑥 < 5.4.9.10019 |
| trueconf | trueconf_server | 5.5.0.13826 ≤ 𝑥 < 5.5.5.10010 |
| trueconf | trueconf_server | 5.5.0.13828 ≤ 𝑥 < 5.5.5.10009 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| trueconf | trueconf | 𝑥 < 5.3 | CNA |
| trueconf | trueconf | 5.3 ≤ 𝑥 < 5.3.9 | CNA |
| trueconf | trueconf | 5.4 ≤ 𝑥 < 5.4.9 | CNA |
| trueconf | trueconf | 5.5 ≤ 𝑥 < 5.5.5 | CNA |
Common Weakness Enumeration