Описание
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-72529
- https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function
- https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
Связанные уязвимости
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Уязвимость программного обеспечения TrueConf Server, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю выполнить произвольный скрипт и повысить свои привилегии
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3