PatchSiren cyber security CVE debrief
CVE-2026-25602 Mesalvo CVE debrief
CVE-2026-25602 is a vulnerability in Mesalvo's MEONA Client and MEONA Server, allowing users with specific administrative roles to send messages with content of their choosing from the server's address to a recipient of their choice. This issue can be used for social engineering and requires access to the hospital's internal network. The vulnerability affects versions 2024.10, 2025.04 (before 2025.04.24), and 2026.03 (before 2026.03.02). Defenders should assess exposure and verify administrative role assignments.
- Vendor
- Mesalvo
- Product
- Meona Client Launcher Component
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-09-25
Who should care
Defenders of hospital networks and systems using MEONA Client and MEONA Server should assess exposure and verify if administrative roles are properly assigned and restricted. This includes reviewing the current role assignments and ensuring that only authorized personnel have access to the MEONA administration area.
Why it matters
CVE-2026-25602 allows users with specific administrative roles to send messages with content of their choosing from the server's address to a recipient of their choice, potentially leading to social engineering attacks. Defenders of hospital networks and systems using MEONA Client and MEONA Server should assess exposure and verify if administrative roles are properly assigned and restricted.
- Social engineering attacks may be possible through crafted messages
- Verification of administrative role assignments and restrictions is necessary
- Mail relay restrictions can limit the impact of the vulnerability
Technical summary
The vulnerability is caused by insufficient verification of data authenticity in the feedback function of MEONA Client and MEONA Server. Users with administrative roles can modify the client request to send a message with content of their choosing from the server's address to a recipient of their choice. This issue affects MEONA Client and MEONA Server in versions 2024.10, 2025.04 (before 2025.04.24), and 2026.03 (before 2026.03.02). The message contains only the recipient, subject and text entered by the user; no data of other users or patients is disclosed.
Defensive priority
Assess exposure of MEONA Client and MEONA Server in your environment, especially if administrative roles are assigned to users who can access the internal network.
Recommended defensive actions
- Assess exposure of MEONA Client and MEONA Server in your environment
- Verify if administrative roles are properly assigned and restricted
- Restrict mail relay to limit recipients of MEONA sender address
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability affects MEONA Client and MEONA Server in versions 2024.10, 2025.04 (before 2025.04.24), and 2026.03 (before 2026.03.02). The feedback function is available only in the MEONA administration area, which requires one of the administrative roles ADMINISTRATOR, SUPERADMINISTRATOR or TYPIST (catalogue editing), or the PHARMACIST role holding the PHARMACY_ADMINISTRATOR right, assigned explicitly by the operating hospital's administrators. Such a user who modifies the client request can cause the MEONA Server to send a with
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25602 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25602
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25602 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25602
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://mesalvo.com/en/vdp/advisories/msa-2026-005.pdf
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.