🔴 CVE-2026-72529

CVE-2026-72529 is a critical missing-authentication flaw in TrueConf Server that allows a remote, unauthenticated attacker to execute arbitrary scripts by calling an undocumented function over TCP port 4307. This is a server-side vulnerability in internet-facing video conferencing infrastructure, actively exploited in the wild by the Head Mare threat actor group and listed in CISA KEV.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-08-19

Added to CISA KEV: 2026-08-20 1 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-14)

Summary

CVE-2026-72529 is a critical vulnerability affecting TrueConf Server that arises from missing authentication for an undocumented function. By sending specially crafted requests to the server's TCP port 4307, a remote, unauthenticated attacker can execute arbitrary scripts on the host system. This vulnerability is significant because it allows for full system compromise, posing a severe risk to the confidentiality, integrity, and availability of affected organizations' video conferencing infrastructure.

Exploitation

  • Active Exploitation: The vulnerability is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog [4][5].
  • Threat Actors: The "Head Mare" threat actor group has been observed using this vulnerability to gain initial access to TrueConf servers [3].
  • Availability: While public proof-of-concept code may be circulating, the confirmed active use by sophisticated threat actors indicates that exploit tooling is readily available to malicious parties.
  • Attack Prerequisites: The attack is remote, requires network access to port 4307/TCP, and does not require authentication or user interaction [1][2].

Affected Products & Patches

  • Affected Versions: TrueConf Server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, and 5.5.X to 5.5.5 are known to be vulnerable [2].
  • Patches/Hotfixes: Users are advised to check official TrueConf security advisories and update to the latest patched version to remediate the vulnerability.
  • Mitigations: Restricting access to port 4307/TCP via firewall rules to trusted networks only can serve as a temporary mitigation, though upgrading the software is necessary to fully address the underlying issue.

Impact

  • Access/Capability: Successful exploitation grants an attacker the ability to execute arbitrary commands/scripts with the privileges of the TrueConf service, effectively providing full system control [1].
  • Business Risk: For internet-facing deployments, this vulnerability presents a critical business risk, as it can lead to complete compromise of the server, unauthorized access to sensitive meeting data, and potential lateral movement into the broader internal corporate network.

Sources

  1. CVE-2026-72529 - Vulnerability Details - OpenCVE

    An unauthenticated attacker with access to the TrueConf Server port 4307/TCP can trigger an undocumented function that lets them execute arbitrary scripts. Because the function lacks authentication checks, the attacker can run any commands on the host, potentially gaining full control and compromisi…

  2. NVD-CVE-2026-72529

    CVE-2026-72529 Detail Description A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

  3. TrueConf flaws enabling attacks on meeting participants ...

    Kaspersky discovered that Head Mare attackers were using CVE-2026-72529 to gain initial access to TrueConf servers; the vulnerability enables ...

  4. CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability; CVE-2026-72530 TrueConf Server Code Injection ...

  5. CISA Cyber (@CISACyber) on X

    🛡️We added TrueConf Server vulnerabilities CVE-2026-72529 & CVE-2026-72530 to our Known Exploited Vulnerabilities Catalog.