TrueConf Product Security Update Advisory

TrueConf Product Security Update Advisory
  • A security update has been released to address vulnerabilities found in TrueConf products.
  • The affected product is TrueConf Server, and the Affected Versions are as follows:
    • Versions prior to 5.3.
    • Versions in the 5.3.X series prior to 5.3.9.
    • Versions 5.4.X prior to 5.4.9.
    • Versions 5.5.X prior to 5.5.5.
  • Two vulnerabilities have been addressed.
    • CVE-2026-72529: An arbitrary script execution vulnerability in TrueConf Server that is triggered through an undocumented function call.
    • CVE-2026-72530: An arbitrary code execution vulnerability in TrueConf Server caused by an escape from the sandbox.
  • Vulnerability Patches have been provided via the latest update.
  • Follow the guidance to update TrueConf Server to the following versions or higher.
    • For version 5.3.X, update to version 5.3.9 Or later.
    • For version 5.4.X, update to version 5.4.9 Or later.
    • For version 5.3.X, version 5.3.9 Or higher.
  • The following reference sites are provided: KLCERT-26-057: TrueConf Server. Missing authentication for critical function and KLCERT-26-058: TrueConf Server. Breakout from isolated environment.