{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-72529",
  "revision": 1,
  "title": "TrueConf Server — Unauthenticated Script Execution via Undocumented Function",
  "summary": "TrueConf Server exposes an undocumented function on port 4307 that needs no login. Anyone who can reach that port on versions up to 5.3.9, 5.4.9 or 5.5.5 can call it and run an arbitrary script on the server.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.3,
    "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
    "version": "4.0"
  },
  "epss": 0.01554,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-08-20",
    "prerequisites": "Network access to TrueConf Server on port 4307"
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Update TrueConf Server per the vendor advisory and restrict port 4307 to trusted networks until done; review exposed servers for signs of compromise.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-72529",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-72529",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-72529",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "tags"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-72529",
      "retrieved_at": "2026-09-21T07:15:12.147Z",
      "confidence": "high",
      "extractor": "human"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72529",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "exploit",
      "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
    },
    {
      "type": "writeup",
      "url": "https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/"
    }
  ],
  "published_at": "2026-08-19T17:21:00.990Z",
  "issued_at": "2026-09-21T07:05:11.841Z",
  "tags": [
    "trueconf",
    "missing-authentication",
    "video-conferencing"
  ]
}
