CVE-2026-3502HIGH 7.8CISA KEVEPSS p92.1%
CVE-2026-3502TrueConf Client Download of Code Without Integrity Check Vulnerability
TrueConf / Client
Description
TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
Scoring
| CVSS 3.1 | 7.8 (HIGH) |
| Vector | CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L |
| EPSS | 5.75% probability of exploitation · percentile 92.1% · 2026-06-19T12:03:05Z |
| Published | 2026-03-30 |
| Last modified | 2026-04-03 |
CISA KEV entry
Added to KEV: 2026-04-02
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Download of Code Without Integrity Checkcwe-494 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | TrueConf Client Download of Code Without Integrity Check Vulnerabilitykev-cve-2026-3502 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.