A security update has been released to address vulnerabilities found in TrueConf products.
The affected product is TrueConf Server, and the Affected Versions are as follows:
Versions prior to 5.3.
Versions in the 5.3.X series prior to 5.3.9.
Versions 5.4.X prior to 5.4.9.
Versions 5.5.X prior to 5.5.5.
Two vulnerabilities have been addressed.
CVE-2026-72529: An arbitrary script execution vulnerability in TrueConf Server that is triggered through an undocumented function call.
CVE-2026-72530: An arbitrary code execution vulnerability in TrueConf Server caused by an escape from the sandbox.
Vulnerability Patches have been provided via the latest update.
Follow the guidance to update TrueConf Server to the following versions or higher.
For version 5.3.X, update to version 5.3.9 Or later.
For version 5.4.X, update to version 5.4.9 Or later.
For version 5.3.X, version 5.3.9 Or higher.
The following reference sites are provided: KLCERT-26-057: TrueConf Server. Missing authentication for critical function and KLCERT-26-058: TrueConf Server. Breakout from isolated environment.