Executive brief
Mesalvo Meona, a healthcare application used for patient management, contains a vulnerability in its administrative SQL interface. An authorized user with high-level privileges can exploit this interface to export sensitive user data, including cleartext passwords, and potentially perform NTLM relay attacks. This could lead to a total compromise of user accounts and lateral movement within the organization's network.
Technical details
An incorrect privilege assignment vulnerability (CWE-266) exists in the Mesalvo Meona Client Launcher and Server components. The application provides an accessible SQL interface that fails to properly restrict sensitive data access or dangerous stored procedures. A remote attacker with high-level administrative privileges can utilize this interface to bypass logging mechanisms and extract cleartext passwords for all users. Additionally, the interface can be abused to initiate NTLM relay attacks via active SQL stored procedures. The vulnerability was identified during a red team engagement and affects Meona Server versions through 2025.04 5+323020.
Affected products
- Mesalvo Meona Client Launcher Component through 19.06.2020 15:11:49
- Mesalvo Meona Server Component through 2025.04 5+323020
Timeline
- 2026-01-08: other: Requested CVE identifiers and notified manufacturer
- 2026-01-12: other: Received CVE identifiers
- 2026-05-13: disclosed: Initial blog post release by SecCore
- 2026-05-20: advisory: NVD publication date