Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-72530

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 27.2%
CVSS Severity
CVSS v3 Score 9.0
Proposed Action
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Ransomware Campaign
Unknown
Products affected by CVE-2026-72530


Contact Us

Shodan ® - All rights reserved