TrueConf Server < 5.3.9.10013 / 5.4.9.10018 / 5.5.5.10010 Multiple Vulnerabilities

critical Nessus Plugin ID 345895

Synopsis

The version of TrueConf Server for Windows / Linuxinstalled on the remote host is affected by multiple vulnerabilities.

Description

The version of TrueConf Server installed on the remote host is prior to 5.3.9.10013, 5.4.9.10018, or 5.5.5.10010. It is, therefore, affected by multiple vulnerabilities:

- A remote unauthenticated attacker connecting to TrueConf Server over 4307/TCP can invoke an undocumented critical function and execute an arbitrary script on the server. (CVE-2026-72529)

- A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. (CVE-2026-72530)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update to TrueConf Windows Server version 5.3.9.10013 / 5.4.9.10018 / 5.5.5.10010 or later.

See Also

http://www.nessus.org/u?c84f2184

Plugin Details

Severity: Critical

ID: 345895

File Name: trueconf_server_5_5_5_10010.nasl

Version: 1.3

Type: Local

Agent: windows

Family: Misc.

Published: 9/15/2026

Updated: 9/16/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.3

Percentile: 99.82

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-72529

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.5

Threat Score: 9.5

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVSS Score Source: CVE-2026-72530

Vulnerability Information

CPE: cpe:/a:trueconf:trueconf_server

Required KB Items: installed_sw/TrueConf Server

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/11/2026

Vulnerability Publication Date: 6/11/2026

CISA Known Exploited Vulnerability Due Dates: 8/23/2026, 9/3/2026

Reference Information

CVE: CVE-2026-72529, CVE-2026-72530