Executive brief
TrueConf Server is a communication and collaboration platform that runs on enterprise servers. A critical vulnerability allows unauthenticated attackers on the network to inject malicious code that escapes the application's security sandbox and executes with full system privileges, potentially compromising the entire server and all data processed by it.
Technical details
TrueConf Server is vulnerable to code injection via port 4307/TCP, which fails to properly sanitize or validate user-supplied script input. The vulnerability allows an unauthenticated remote attacker to craft a specially designed script that breaks out of the application's isolated execution environment and achieves arbitrary code execution on the host system. No authentication is required to exploit this vulnerability, and the attack is triggered over the network. An attacker can achieve complete system compromise, including privilege escalation, data exfiltration, and lateral movement. This vulnerability has been actively exploited in the wild.
Affected products
- TrueConf Server
Timeline
- 2026-08-20: disclosed
- exploited: Actively exploited in the wild