Vulnerability
Published 2026-08-20
Verified 2026-09-19

TrueConf Server missing authentication on port 4307 (CVE-2026-72529)

Kaspersky ICS CERT (KLCERT-26-057): an unauthenticated attacker with network access to TrueConf Server on TCP 4307 can call an undocumented function and run an arbitrary script. Affects 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and earlier than 5.3. NVD CVSS 9.8. Related CVE-2026-72530 is a code-injection issue in the same product line. Patch to the fixed builds and do not expose 4307 to the internet.

Product
TrueConf Server
Versions
5.3.x < 5.3.9; 5.4.x < 5.4.9; 5.5.x < 5.5.5; and earlier than 5.3
CVSS
(CVSS 3.1, NVD)
Exploited in Australia?
unknown
Patch to
5.3.9 / 5.4.9 / 5.5.5 or later

Primary: Kaspersky ICS CERT KLCERT-26-057 · Vendor: NVD · CVE: CVE-2026-72529, CVE-2026-72530

vulnerabilities