Skip to content

Security Fixes Updates And Advisories

trueconf.com August 21, 2026

Security updates are an important part of maintaining a secure TrueConf deployment. This page provides information publicly disclosed vulnerabilities affecting TrueConf products, including affected versions, severity levels, CVSS scores, technical impact, and available fixes.

The vulnerability table below is intended to help administrators identify whether a deployed version of TrueConf Server or TrueConf Client may be affected by a known security issue and determine whether an update is required.

Each vulnerability entry includes:

CVE — the unique identifier assigned to the vulnerability; Product — the affected TrueConf product; Affected version — the version or version range known to be affected; Vulnerability — the general vulnerability type, such as SQL injection, cross-site scripting, or DLL hijacking; CVSS severity — the severity classification derived from the published CVSS base score; CVSS — the published Common Vulnerability Scoring System score.

Select a CVE entry to view additional information the vulnerability, including the affected component, attack conditions, potential impact, CVSS vector, and the fixed version when this information is available.

Improper management of code generation can allow an attacker who has achieved code execution in the TrueConf Server isolated environment to escape the sandbox and execute arbitrary commands on the underlying operating system.

Isolated execution environment / code generation

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

BDU:2026-11247; KLCERT-26-058

Resolution: 5.3.9 / 5.4.9 / 5.5.5

A remote unauthenticated attacker connecting to TrueConf Server over 4307/TCP can invoke an undocumented critical function and execute an arbitrary script on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Resolution: 5.3.9 / 5.4.9 / 5.5.5

The client update mechanism can apply downloaded update code without sufficient verification, allowing a malicious update source to deliver arbitrary code.

Insufficient protection of service data can allow a remote attacker to initiate a request on behalf of the TrueConf Server.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Resolution: 5.5.2.11029 Windows / 5.5.2.11041 Linux; 5.4.8.10015 Windows / 5.4.8.10016 Linux

A relative-path handling flaw can allow a remote attacker to delete an arbitrary file and cause denial of service.

Server method / path handling

Resolution: 5.5.2.11029 Windows / 5.5.2.11041 Linux; 5.4.8.10015 Windows / 5.4.8.10016 Linux

A relative-path handling flaw in a TrueConf Server method can allow a remote attacker to execute arbitrary code.

Server method / path handling

Resolution: 5.5.2.11029 Windows / 5.5.2.11041 Linux; 5.4.8.10015 Windows / 5.4.8.10016 Linux

Differences in responses to incoming requests can allow a remote attacker to determine information a property of an object.

Server response handling

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Improper neutralization of special elements can allow a remote attacker to execute arbitrary commands and cause denial of service.

Server input handling

Resolution: 5.5.3, 5.4.8

Improper neutralization of special elements can allow remote execution of arbitrary operating-system commands.

Server input handling

See BDU/CyberOK advisory

Insufficient limitation of authentication attempts can allow a remote attacker to perform brute-force attacks.

Authentication mechanism

Resolution: 5.5.2, 5.4.7, 5.3.8

Weaknesses in the authorization procedure can allow a remote attacker to bypass existing security restrictions.

Authorization mechanism

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Resolution: 5.5.2, 5.4.7, 5.3.8

Insufficient protection of web-page structure can allow a remote attacker to perform a reflected cross-site scripting attack.

BDU CVSS 3.1 score 6.3

Resolution: 5.5.2, 5.4.7, 5.3.8

Improper neutralization of special elements can allow a remote attacker to execute arbitrary operating-system commands.

Server command handling

Resolution: 5.5.1, 5.4.6, 5.3.7

A relative-path handling vulnerability can allow an attacker to read arbitrary files on the system.

Public reporting commonly cites CVSS 7.5

Resolution: 5.5.1, 5.4.6, 5.3.7

Insufficient access control can allow requests to certain administrative endpoints under /admin/* without authentication.

Administrative endpoints

Resolution: 5.5.1, 5.4.6, 5.3.7

A crafted wfapi.dll can allow a local attacker to execute arbitrary code in the user's context.

A normal user can inject malicious spreadsheet formulas into exported chat logs through a crafted Display Name.

Stored XSS in the Meeting location field can execute on the Conference Info page and may lead to account takeover.

HTML injection in the conference description can trigger when a victim opens the Conference Info page.

Conference description

A remote unauthenticated attacker can execute arbitrary SQL through the web API, potentially resulting in remote code execution.

Resolution: 5.2.6.10025

A low-privileged database user can execute arbitrary SQL as the database administrator through a stored function.

Database stored function

Resolution: 5.2.6.10025

Cross-site request forgery affects /admin/service/stop/.

An open redirect issue affects /admin/general/change-lang via redirect_url.

DOM-based XSS affects /admin/conferences/list/ via domxss.

DOM-based XSS affects /admin/group.

Reflected XSS affects /admin/group/list/ via checked_group_id.

Reflected XSS affects /admin/conferences/list/ via sort.

Reflected XSS affects /admin/conferences/get-all-status/ via keys[].

A stored cross-site scripting vulnerability affects TrueConf Server 4.3.7.

Not specified in source

Administrators should keep TrueConf software up to date and review security information when new vulnerabilities are disclosed.

When a fixed version is listed, upgrading to that version or a newer supported release is recommended. If the public CVE record does not identify a specific fixed version, the entry on this page indicates this explicitly rather than inferring a remediation version.

The information provided here is based on publicly available CVE records and related vulnerability disclosures. Details may be updated as additional technical information becomes available.

Where can I find information TrueConf security flaws?

Security flaws affecting TrueConf products may require updating the affected software or reviewing its security configuration.

For information authentication, encryption, administrator access, data protection, and other security mechanisms, see the TrueConf Server security documentation . For flaws addressed by newer releases, also check the TrueConf Release Notes.

How can I resolve TrueConf security issues?

The appropriate action depends on the type of security issue.

For HTTPS and access configuration, see the Web and HTTPS settings . For authentication, data protection, permissions, and other security settings, use the TrueConf Server security documentation .

If the issue is corrected in a newer product version, follow the official update instructions before upgrading.

Where can I find TrueConf security updates?

Security-related releases are covered in TrueConf product update announcements and release information.

For recent TrueConf Server recommendations, see TrueConf Server: Security Updates for June 2026 . The complete product release history is available in the TrueConf Release Notes .

TrueConf Server update procedures are described in the Installation and Update documentation.

How are TrueConf security patches installed?

Security corrections are generally delivered as part of TrueConf product updates rather than through a separate patch catalog.

Check the required product version in the TrueConf Release Notes , then follow the TrueConf Server Installation and Update guide to deploy the update.

For security releases published in June 2026, also review the TrueConf Server security update announcement .

What should I do if a TrueConf exploit is reported?

Determine which TrueConf product and version are affected and compare them with the software deployed in your environment.

Then check the TrueConf Release Notes and current security update announcements for an updated version. TrueConf Server administrators should use the official update procedure when installing the recommended release.

What should I do if a TrueConf zero-day vulnerability is reported?

For a newly disclosed security problem, first check current TrueConf product announcements and the TrueConf Release Notes to determine whether an updated version is available.

Until remediation information is published, administrators should also review the relevant settings in the TrueConf Server security documentation and restrict unnecessary access to affected services where appropriate.