Trueconf · Trueconf Server · CVE-2026-72530
**Name of the Vulnerable Software and Affected Versions**
TrueConf server versions 5.3.0 through 5.3.9
TrueConf server versions 5.4.0 through 5.4.9
TrueConf server versions 5.5.0 through 5.5.5
TrueConf server versions prior to 5.3.0
**Description**
Improper management of code generation allows a remote unauthorized attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment (sandbox) and execute arbitrary code on the host operating system. Real-world exploitation of this issue has been recorded.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.