11 August 2026
KLCERT-26-057: TrueConf Server. Missing authentication for critical function
Vendor
TrueConf
-
CVE
-
KLCERT
KLCERT-26-057
Timeline
Timeline
-
Kaspersky ICS CERT advisory published
07 August 2026
-
Vendor Informing
August 2026
Description
An unauthorized remote attacker with network access via port 4307/TCP to TrueConf server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5, as well as all versions before 5.3, could execute an arbitrary script by calling an undocumented function.
CVSS v3 Base Score
Exploitability
Remotely
Attack complexity
Privilege required
User interaction
Confidentiality
Integrity
High
Availability
High
Impact
Affected products
TrueConf Server (for Windows and Linux):
- All versions before 5.3
- 5.3.X before 5.3.9
- 5.4.X before 5.4.9
- 5.5.X before 5.5.5
Mitigation
- Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5.
- Perform a full check with antivirus software that has up-to-date antivirus databases and modules.
- Conduct a scan for indicators of compromise specified in the threat alert “Head Mare APT group exploits vulnerabilities in TrueConf server to deliver PhantomCore malware to conference participants”. In the event that any indicators of compromise are detected, change the passwords for all potentially affected accounts and contact us at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident.
Timeline
-
Kaspersky ICS CERT advisory published
07 August 2026
-
Vendor Informing
August 2026