Junglewise Threat Intelligence

CVE-2026-72529: TrueConf Server missing authentication for critical function

CVE-2026-72529 · Severity: critical · Exploited in the wild · Published 2026-08-20

Executive brief

TrueConf Server is a video conferencing and unified communications platform used by organizations to enable remote collaboration. A missing authentication vulnerability in the server allows unauthenticated attackers to execute arbitrary scripts remotely over the network, potentially leading to complete system compromise, data theft, and service disruption.

Technical details

TrueConf Server fails to implement proper authentication checks on a critical functionality exposed on port 4307/TCP. An unauthenticated attacker on the network can directly invoke this function without providing credentials, leading to arbitrary script execution on the server. The vulnerability is an authentication bypass (CWE-306: Missing Authentication for Critical Function) that requires only network access to the affected port. Since the vulnerability has been observed in active exploitation, attackers can leverage this to gain code execution, establish persistence, exfiltrate data, or pivot within the target network. Patches or updates should be applied immediately to enable authentication controls on the exposed functionality.

Affected products

  • TrueConf TrueConf Server

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: exploited

Related threats