Back to Live Pulse
Critical
Trueconf server
Code Injection

CVE-2026-72530

Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Proof of Concept (POC) Links

Explore how this vulnerability can be reproduced or exploited.