Junglewise Threat Intelligence

CVE-2026-0857: Mesalvo Meona cleartext storage of sensitive information in memory

CVE-2026-0857 · Severity: medium · CVSS 6 · Published 2026-05-20

Technologies: Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. Vendors: Mesalvo.

Executive brief

Mesalvo Meona is a healthcare application used for patient management. A security flaw allows sensitive information, including user passwords, to be stored in plain text within the system's memory and administrative interfaces. An attacker with high-level access could exploit this to steal credentials, potentially leading to unauthorized access to patient data or further movement into the corporate network.

Technical details

The Mesalvo Meona application suffers from a cleartext storage of sensitive information vulnerability (CWE-316). During a security assessment, it was discovered that the application stores certain user passwords in plaintext and others using the weak MD5 hashing algorithm, both of which are accessible via the administrative panel and memory. An attacker with administrative privileges (PR:H) can retrieve these credentials to perform lateral movement or password spraying attacks. The vulnerability affects the Client Launcher (up to version 19.06.2020 15:11:49) and the Server Component (up to version 2025.04 5+323020). While the CVSS vector indicates local access, the context of the research suggests this was leveraged during a red team engagement to escalate privileges and move laterally.

Affected products

  • Mesalvo Meona Client Launcher Component through 19.06.2020 15:11:49
  • Mesalvo Meona Server Component through 2025.04 5+323020

Timeline

  • 2026-01-08: other: Notified manufacturer and requested CVE identifiers
  • 2026-01-12: other: Received CVE identifiers
  • 2026-05-13: disclosed: Initial blog post release by SecCore
  • 2026-05-20: advisory: NVD publication date

References

Related threats