CVE-2026-3502

TrueConf Client Update Integrity Verification Bypass

Severity
High 7.8
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Apr 2, 2026
EPSS
0.057
92.7th percentile
Discovered by
Not disclosed
Published
Mar 30, 2026
Assigned by checkpoint

Description

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Weakness: CWE-494

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported products (1)
  • TrueConf · TrueConf Client

Something wrong here?