Missing authentication enables remote script execution in TrueConf Server by TrueConf

What is CVE-2026-72529?

CVE-2026-72529 is a vulnerability classified as Missing Authentication for Critical Function, affecting TrueConf Server (affected versions: < 5.3, 5.3 – < 5.3.9, and other affected versions). This vulnerability is rated Critical, with a CVSS score of 9.3. This vulnerability has been observed being exploited in the wild.

Overview

Original source data

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Affected products and scope

TrueConf Server for Windows and Linux is affected in the following ranges:

  • All versions before 5.3.
  • The 5.3.X branch before 5.3.9.
  • The 5.4.X branch before 5.4.9.
  • The 5.5.X branch before 5.5.5.

The affected data sets the default status to unaffected outside these ranges. The status of parallel or otherwise unlisted release branches should not be inferred without confirmation from TrueConf.

Technical details

TrueConf Server exposes an undocumented function on 4307/TCP without requiring authentication. A remote attacker with network access can call that function and supply an attacker-controlled script for execution on the server. Kaspersky describes the initially received script as running in an isolated environment where operating system functions are not accessible by default. The implementation detail that leaves the function unauthenticated, and the exact script format, have not been publicly described. In the observed campaign, this vulnerability was used as an initial stage and combined with a separate vulnerability to escape the isolated environment and execute operating-system commands.

Exploitability

The vulnerability is remotely reachable over the network through 4307/TCP and requires neither authentication nor user interaction. Kaspersky describes the exploitation complexity as low. Exploitation has been observed in the wild: Kaspersky reported that the Head Mare group used this vulnerability in an attack chain against unpatched TrueConf Server deployments, followed by delivery of PhantomCore and PhantomGraph. Public technical detail shows the first stage calling a server function to transmit and execute a malicious script; the complete attack chain also required a separate vulnerability to obtain operating-system-level execution.

Technical impact

  • The vulnerability permits unauthorized remote script execution on the TrueConf Server itself, with potential effects on the system's confidentiality, integrity, and availability.
  • The public description confirms script execution but does not establish that this step alone always provides the highest operating-system privileges.
  • In the attack investigated by Kaspersky, a second vulnerability was used to escape the isolated environment; the attackers then executed code in the context of NT AUTHORITY\SYSTEM, maintained control, accessed the database, and modified client installers.
  • Possible organizational consequences include loss of control over the conferencing server, exposure of infrastructure or account data, service disruption, and malware delivery to conference participants. These consequences reflect the observed attack chain and should not be interpreted as guaranteed results of every standalone exploitation attempt.

Business impact

  • An attacker can execute a script on the conferencing server without an account, creating a risk of unauthorized changes to system configuration, data, or service operation.
  • In the campaign investigated by Kaspersky, the attack chain was used to obtain high-privilege code execution, collect infrastructure information, access the TrueConf database, and replace the TrueConf Client distribution with a version containing PhantomCore.
  • An organization's users may be affected indirectly if they download a tampered installer from a compromised TrueConf Server, even when the organization does not operate its own server.
  • The initial script-execution stage may be constrained by the isolated environment, but operational risk is substantially higher when this vulnerability is combined with another vulnerability in the same attack chain.

Remediation

  1. Update TrueConf Server according to the deployed branch: update the 5.3 branch to 5.3.9, the 5.4 branch to 5.4.9, or the 5.5 branch to 5.5.5. Do not replace this branch-specific guidance with an assumption that every other release is fixed.
  2. If updating is not immediately possible, reduce network exposure of 4307/TCP according to the organization's operating procedures and prevent access from untrusted networks. This reduces exposure but is not a confirmed software fix.
  3. Perform a full check with antivirus software that has current databases and modules.
  4. Scan for the campaign-related IOCs described by Kaspersky. If compromise indicators are found, isolate the system under the incident-response process, change passwords for potentially affected accounts, and contact Kaspersky ICS CERT for investigation assistance.
  5. Verify the digital signature and integrity of TrueConf Client packages downloaded from the server before distributing them to users.

Detection

  1. Inventory all TrueConf Server deployments and identify systems reachable through 4307/TCP; compare each installation with the affected branches.
  2. On Windows, review creation or replacement of …\public\js\locale.php, suspicious files created by TrueConf processes, and TrueConf installers that lack a valid software signature.
  3. Check for the registry key HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32 and Windows services named SysExcSvc or SysReadSvc.
  4. Review telemetry for access to or memory dumps of lsass.exe, SSH tunnel creation, and suspicious process chains originating from the TrueConf update process.
  5. Ensure that Windows Security events 4688, 4663, 4657, and 4697, together with Sysmon events 1, 7, 11, and 13, are collected. Use the IOC list and detection guidance published by Kaspersky for investigation; the absence of these indicators does not prove that exploitation did not occur.
Sources (8)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard