Back to Live Pulse
Critical
Trueconf server
Missing Authentication for Critical Function

CVE-2026-72529

Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Proof of Concept (POC) Links

Explore how this vulnerability can be reproduced or exploited.