11 August 2026

KLCERT-26-057: TrueConf Server. Missing authentication for critical function

Vendor

TrueConf

Researcher

Vyacheslav KopeytsevPrincipal Security Researcher

Timeline

Timeline

  • Kaspersky ICS CERT advisory published

    07 August 2026

  • Vendor Informing

    August 2026

Description

An unauthorized remote attacker with network access via port 4307/TCP to TrueConf server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5, as well as all versions before 5.3, could execute an arbitrary script by calling an undocumented function.


Exploitability

Remotely

Attack complexity

Low

Privilege required

None

User interaction

None

Confidentiality

High

Integrity

High

Availability

High

Impact

Successful exploitation of this vulnerability could enable an attacker with network access to the target system to execute arbitrary scripts on the TrueConf server.

Affected products

TrueConf Server (for Windows and Linux):

  • All versions before 5.3
  • 5.3.X before 5.3.9
  • 5.4.X before 5.4.9
  • 5.5.X before 5.5.5

Mitigation

Timeline

  • Kaspersky ICS CERT advisory published

    07 August 2026

  • Vendor Informing

    August 2026