PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25602 Mesalvo CVE debrief

CVE-2026-25602 is a vulnerability in Mesalvo's MEONA Client and MEONA Server, allowing users with specific administrative roles to send messages with content of their choosing from the server's address to a recipient of their choice. This issue can be used for social engineering and requires access to the hospital's internal network. The vulnerability affects versions 2024.10, 2025.04 (before 2025.04.24), and 2026.03 (before 2026.03.02). Defenders should assess exposure and verify administrative role assignments.

Vendor
Mesalvo
Product
Meona Client Launcher Component
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-20
Original CVE updated
2026-09-25
Advisory published
2026-05-20
Advisory updated
2026-09-25

Who should care

Defenders of hospital networks and systems using MEONA Client and MEONA Server should assess exposure and verify if administrative roles are properly assigned and restricted. This includes reviewing the current role assignments and ensuring that only authorized personnel have access to the MEONA administration area.

Why it matters

CVE-2026-25602 allows users with specific administrative roles to send messages with content of their choosing from the server's address to a recipient of their choice, potentially leading to social engineering attacks. Defenders of hospital networks and systems using MEONA Client and MEONA Server should assess exposure and verify if administrative roles are properly assigned and restricted.

  • Social engineering attacks may be possible through crafted messages
  • Verification of administrative role assignments and restrictions is necessary
  • Mail relay restrictions can limit the impact of the vulnerability

Technical summary

The vulnerability is caused by insufficient verification of data authenticity in the feedback function of MEONA Client and MEONA Server. Users with administrative roles can modify the client request to send a message with content of their choosing from the server's address to a recipient of their choice. This issue affects MEONA Client and MEONA Server in versions 2024.10, 2025.04 (before 2025.04.24), and 2026.03 (before 2026.03.02). The message contains only the recipient, subject and text entered by the user; no data of other users or patients is disclosed.

Defensive priority

Assess exposure of MEONA Client and MEONA Server in your environment, especially if administrative roles are assigned to users who can access the internal network.

Recommended defensive actions

  • Assess exposure of MEONA Client and MEONA Server in your environment
  • Verify if administrative roles are properly assigned and restricted
  • Restrict mail relay to limit recipients of MEONA sender address
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability affects MEONA Client and MEONA Server in versions 2024.10, 2025.04 (before 2025.04.24), and 2026.03 (before 2026.03.02). The feedback function is available only in the MEONA administration area, which requires one of the administrative roles ADMINISTRATOR, SUPERADMINISTRATOR or TYPIST (catalogue editing), or the PHARMACIST role holding the PHARMACY_ADMINISTRATOR right, assigned explicitly by the operating hospital's administrators. Such a user who modifies the client request can cause the MEONA Server to send a with

Sources and references

Verified primary and authoritative sources

  • CVE-2026-25602 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-25602

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-25602 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25602

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://mesalvo.com/en/vdp/advisories/msa-2026-005.pdf

    a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.