Junglewise Threat Intelligence

CVE-2026-0856: Mesalvo Meona improper access control in admin panel

CVE-2026-0856 · Severity: high · CVSS 7.8 · Published 2026-05-20

Technologies: Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. Vendors: Mesalvo.

Executive brief

Mesalvo Meona is a healthcare application used to manage patient data and clinical workflows. A security flaw in how the system checks user permissions allows a standard user to bypass security restrictions and access the administrative control panel. This could lead to unauthorized access to sensitive patient information, system configurations, and full control over the application's administrative functions.

Technical details

The vulnerability is classified as Improper Access Control (CWE-284) within the Meona Client Launcher and Server components. The root cause is a failure of the backend server to verify the authorization levels of provided user credentials when accessing administrative interfaces. An attacker with low-privileged local access to the application can bypass client-side restrictions to interact with the admin panel. This allows for full control over data and functions within the portal, which can be further leveraged for lateral movement or data exfiltration. The issue was identified in Meona Server version 2025.04 5+323020 and Client Launcher version 19.06.2020 15:11:49.

Affected products

  • Mesalvo Meona Client Launcher Component through 19.06.2020 15:11:49
  • Mesalvo Meona Server Component through 2025.04 5+323020

Timeline

  • 2026-01-08: other: Notified manufacturer and requested CVE identifiers
  • 2026-01-12: other: Received CVE identifiers
  • 2026-05-13: disclosed: Initial blog post release by SecCore
  • 2026-05-20: advisory: NVD publication date

References

Related threats