{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72529","assignerOrgId":"e45d732a-8f6b-4b6b-be76-7420f6a2b988","state":"PUBLISHED","assignerShortName":"Kaspersky","dateReserved":"2026-08-10T09:55:18.375Z","datePublished":"2026-08-19T16:55:14.949Z","dateUpdated":"2026-08-21T03:55:16.895Z"},"containers":{"cna":{"providerMetadata":{"orgId":"e45d732a-8f6b-4b6b-be76-7420f6a2b988","shortName":"Kaspersky","dateUpdated":"2026-08-19T16:55:14.949Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","type":"CWE"}]}],"affected":[{"vendor":"TrueConf","product":"TrueConf Server","platforms":["Windows","Linux"],"versions":[{"version":"*","status":"affected","lessThan":"5.3","versionType":"custom"},{"version":"5.3","status":"affected","lessThan":"5.3.9","versionType":"custom"},{"version":"5.4","status":"affected","lessThan":"5.4.9","versionType":"custom"},{"version":"5.5","status":"affected","lessThan":"5.5.5","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function."}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0"},"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5."}],"workarounds":[{"lang":"en","value":"Perform a full check with anti-virus software that has up-to-date anti-virus databases and software modules."},{"lang":"en","value":"Conduct a scan for indicators of compromise. In the event of detecting indicators of compromise, change passwords for accounts that may have been compromised and contact Kaspersky ICS CERT at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident."}],"timeline":[{"time":"2026-08-03T00:00:00.000Z","lang":"en","value":"Issue discovered by Kaspersky ICS CERT and reported to TrueConf"},{"time":"2026-08-04T00:00:00.000Z","lang":"en","value":"Issue confirmed by TrueConf"},{"time":"2026-08-07T00:00:00.000Z","lang":"en","value":"Advisory published by Kaspersky ICS CERT"}],"credits":[{"lang":"en","value":"Vyacheslav Kopeytsev from Kaspersky ICS CERT","type":"finder"}],"references":[{"url":"https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/","name":"KLCERT-26-057: TrueConf Server. Missing Authentication for Critical Function","tags":["third-party-advisory"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-19T00:00:00+00:00","options":[{"Exploitation":"active"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-72529"}}},{"other":{"type":"kev","content":{"dateAdded":"2026-08-20","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529"}}}],"references":[{"url":"https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/","tags":["related"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529","tags":["government-resource"]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-21T03:55:16.895Z"},"timeline":[{"time":"2026-08-20T00:00:00.000Z","lang":"en","value":"CVE-2026-72529 added to CISA KEV"}]}]}}