← Back to browse · API

CVE-2026-3502

Severity
HIGH
CVSS
7.8
EPSS
0.0575
Risk score
58.21
CISA KEV
Yes
PoC
No
Published
2026-04-02
Modified
2026-04-02
First seen
2026-08-07
Aliases
EUVD-2026-17162, GHSA-33R5-G5M3-5M79
Products
TrueConf:Client, TrueConf:TrueConf Client TrueConf Client versions 8.1.0 through 8.5.2
Sources
cisa.gov CVE-2026-3502
euvd EUVD-2026-17162

Description

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

References