Junglewise Threat Intelligence

CVE-2026-22314: Mesalvo Meona code injection in Client Launcher and Server components

CVE-2026-22314 · Severity: critical · CVSS 9 · Published 2026-05-20

Technologies: Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. Vendors: Mesalvo.

Executive brief

Mesalvo Meona is a healthcare management application used to manage patient data and clinical workflows. A vulnerability in the system allows an attacker with basic user access to inject malicious scripts or configurations that execute on other users' computers. This could lead to a total compromise of clinical workstations, unauthorized access to sensitive patient records, and lateral movement across the healthcare provider's network.

Technical details

A code injection vulnerability exists in the Mesalvo Meona Client Launcher and Server components. The flaw stems from improper control of code generation within administrative features, where the application allows the addition of scripts in various programming languages or the modification of XML-based configurations. An attacker with low-privileged credentials can abuse these features to push malicious code that is subsequently executed on other client systems running Meona. This vulnerability was identified during a red team engagement and can be used for lateral movement within the target network. While the manufacturer has indicated plans to release patches in May/June 2026, users should monitor for unauthorized changes to script configurations within the Meona admin interface.

Affected products

  • Mesalvo Meona Client Launcher Component through 19.06.2020 15:11:49
  • Mesalvo Meona Server Component through 2025.04 5+323020

Timeline

  • 2026-01-08: other: Requested CVE identifiers and notified manufacturer
  • 2026-01-12: other: Received CVE identifiers
  • 2026-05-04: other: Manufacturer requested publication of the CVEs
  • 2026-05-13: disclosed: Initial blog post release by SecCore
  • 2026-05-20: advisory: NVD publication date

References

Related threats