CVE-2026-72529
TrueConf Server missing authentication allows unauthenticated script execution via port 4307/TCP (CVE-2026-72529)
CVE-2026-72529 is a critical (CVSS 9.3) missing authentication flaw in TrueConf Server. A remote attacker with network access to port 4307/TCP can execute an arbitrary script without credentials. CISA KEV records active exploitation; fixed releases are 5.3.9, 5.4.9 and 5.5.5.
What happened
CVE-2026-72529 is a missing authentication for a critical function (CWE-306) in TrueConf Server. The CVE record describes a remote unauthorised attacker with network access to TCP port 4307 calling an undocumented function to execute an arbitrary script. The CVSS 4.0 vector scores it 9.3 (critical), with a network attack vector, low attack complexity, no privileges, no user interaction, and high impact on confidentiality, integrity and availability of the vulnerable host.
CISA added this CVE to its Known Exploited Vulnerabilities catalog on 20 August 2026, with a due date of 23 August 2026. CISA's SSVC assessment rates exploitation as active, automatable, and total technical impact. The references listed with this CVE include a Kaspersky ICS-CERT advisory and a Securelist report.
Who is affected
The affected product is TrueConf Server. The CVE record lists the following affected ranges:
- before 5.3
- 5.3 to before 5.3.9
- 5.4 to before 5.4.9
- 5.5 to before 5.5.5
Exploitation requires network access to TCP port 4307; the flaw allows the undocumented function to be called without credentials. Deployments that expose that port to untrusted networks should treat this as a priority.
What to do now
- Upgrade affected TrueConf Server installations to a fixed release for their branch: TrueConf Server 5.3.9, TrueConf Server 5.4.9 or TrueConf Server 5.5.5.
- If upgrading immediately is not possible, restrict network access to TCP port 4307 to trusted management networks only. Follow CISA KEV required action: apply mitigations in accordance with vendor instructions, evaluate each asset's internet exposure, follow applicable BOD 26-04 guidance, or discontinue use if mitigations are unavailable.
- Treat affected systems as potentially compromised. CISA KEV records active exploitation; if you have not yet patched, review TrueConf Server hosts for unexpected scripts and engage incident response support if you find signs of compromise.
How to detect it
Start with an inventory of TrueConf Server hosts and check whether TCP port 4307 is reachable from the internet or other untrusted segments. The sources provided for this CVE do not include specific indicators of compromise; log review should focus on unexpected connections to port 4307 and unauthorised script execution on the affected server.
Beyond the patch
Because CISA KEV records active exploitation and the flaw is reachable without credentials over a network port, check exposure and detection before the next incident. Managed Detection & Response can provide monitoring for post-exploitation activity, and Virtual CISO Services can help identify exposed TrueConf Server ports and fit them into vulnerability management.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| TrueConf Server | – < 5.3 5.3 – < 5.3.9 5.4 – < 5.4.9 5.5 – < 5.5.5 | 5.3.9 5.4.9 5.5.5 |