CVE Watchtower


← Back to CVE List

CVE-2026-3502NVD

Vulnerability Summary

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
Severity Level
HIGH(7.8)
Published Date
Mar 30, 2026
Last Modified
Apr 3, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
2.63%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredHigh
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityLow