Multiple vulnerabilities in TrueConf Server were disclosed as affecting Windows deployments, including a high-severity authentication bypass tracked as BDU:2025-10114. The flaw stems from an alternative path or channel weakness (CWE-228) that allows remote attackers to send certain API requests without proper authentication, including access to some /admin/* endpoints where authorization checks are not correctly enforced. Russian vulnerability records state the issue affects multiple versions before vendor-fixed releases, that exploit code exists, and that the vulnerability has been observed in attacks.
A related TrueConf Server issue, BDU:2025-10115, allows attackers to read arbitrary files on affected systems, expanding the risk from unauthorized administrative access to potential exposure of sensitive local data. Positive Technologies flagged both BDU:2025-10114 and BDU:2025-10115 as trending vulnerabilities, while a third identifier, BDU:2025-10116, was also listed without public technical details. The vendor has confirmed the disclosed issues and recommends applying the latest software updates and following official remediation guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Positive Technologies reported TrueConf Server vulnerabilities BDU-2025-10114 and BDU-2025-10115 as trending. BDU-2025-10114 involves insufficient access control on certain /admin/* endpoints, while BDU-2025-10115 allows arbitrary file read; in both cases, users were advised to apply the vendor's latest updates.
A high-severity authentication bypass vulnerability affecting multiple TrueConf Server for Windows versions prior to vendor-fixed releases was identified and confirmed by the vendor. The flaw allows remote attackers to send certain API requests without proper authentication, and the entry states exploit code exists and the vulnerability is being used in attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.