A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
History

Thu, 20 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Script Upload in TrueConf Server

Thu, 20 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Trueconf trueconf Server
CPEs cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
Vendors & Products Trueconf trueconf Server

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-08-20T00:00:00+00:00', 'dueDate': '2026-09-03T00:00:00+00:00'}


Thu, 20 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Script on TrueConf Server

Thu, 20 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Script on TrueConf Server

Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Trueconf
Trueconf server
Vendors & Products Trueconf
Trueconf server

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Kaspersky

Published: 2026-08-19T16:56:53.099Z

Updated: 2026-08-21T03:55:18.512Z

Reserved: 2026-08-10T09:55:18.375Z

Link: CVE-2026-72530

cve-icon Vulnrichment

Updated: 2026-08-19T17:16:19.874Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T17:21:01.130

Modified: 2026-08-21T04:18:15.903

Link: CVE-2026-72530

cve-icon Redhat

No data.