Junglewise Threat Intelligence

CVE-2026-25602: Mesalvo Meona insufficient data verification in feedback functionality

CVE-2026-25602 · Severity: medium · CVSS 4.4 · Published 2026-05-20

Technologies: Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. Vendors: Mesalvo.

Executive brief

Mesalvo Meona is a healthcare application used for patient management. A vulnerability in its feedback reporting system allows an attacker to manipulate the destination of outgoing emails. This could be used by a malicious actor to send spoofed internal emails from a legitimate corporate address, facilitating social engineering or phishing attacks against employees.

Technical details

The vulnerability exists because the Meona Server Component fails to verify the recipient email address provided by the client during feedback report submissions. The application utilizes serialized Hessian objects for client-server communication. An attacker can intercept and modify these serialized objects to replace the hardcoded recipient address with an arbitrary one. Because the server does not validate this data against an allowlist or server-side configuration, it processes the request and sends the email to the attacker-specified address using the organization's legitimate internal mail server.

Affected products

  • Mesalvo Meona Client Launcher Component through 19.06.2020 15:11:49
  • Mesalvo Meona Server Component through 2025.04 5+323020

Timeline

  • 2026-01-08: other: Notified manufacturer and requested CVE identifiers
  • 2026-05-13: disclosed: Initial blog post release by SecCore
  • 2026-05-20: advisory: CVE published to NVD

References

Related threats