CVE-2026-72529

EUVD-2026-62587
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
KasperskyCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 72.73%
Affected Products (NVD)
VendorProductVersion
trueconftrueconf_server
𝑥
< 5.3.9.10013
trueconftrueconf_server
𝑥
< 5.3.9.10015
trueconftrueconf_server
5.4.0.12689 ≤
𝑥
< 5.4.9.10072
trueconftrueconf_server
5.4.0.12700 ≤
𝑥
< 5.4.9.10019
trueconftrueconf_server
5.5.0.13826 ≤
𝑥
< 5.5.5.10010
trueconftrueconf_server
5.5.0.13828 ≤
𝑥
< 5.5.5.10009
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
trueconftrueconf
𝑥
< 5.3
CNA
trueconftrueconf
5.3 ≤
𝑥
< 5.3.9
CNA
trueconftrueconf
5.4 ≤
𝑥
< 5.4.9
CNA
trueconftrueconf
5.5 ≤
𝑥
< 5.5.5
CNA