CVE-2026-72529

9.5 CISA KEV

TrueConf · Server

TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.

Executive summary

TrueConf Server is vulnerable to an unauthenticated critical function access flaw that is currently being exploited in the wild.

Vulnerability

This vulnerability, categorized as CWE-306, allows an unauthenticated remote attacker to bypass security controls and execute critical functions on the server. The lack of proper authentication checks exposes the administrative interface to unauthorized interaction.

Business impact

The potential for unauthenticated access to critical server functions poses a severe risk to organizational data and infrastructure integrity. With a CVSS score of 9.5, this vulnerability represents a critical threat level that could lead to full system compromise, unauthorized data exfiltration, or complete service disruption.

Remediation

Immediate Action: Update all instances of TrueConf Server to versions 5.3.9, 5.4.9, or 5.5.5 immediately to resolve the authentication bypass.

Proactive Monitoring: Review server access logs for unusual administrative activity or unauthorized requests originating from unknown or external IP addresses.

Compensating Controls: Implement strict network access control lists to limit exposure of the TrueConf management interface to known, trusted internal management networks only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the confirmed active exploitation and the critical nature of the vulnerability, immediate patching is mandatory. Administrators must prioritize the deployment of the provided updates to secure the environment against ongoing threats targeting this flaw.

More TrueConf CVEs