Exploitation requires a MEONA account with one of the administrative roles named above and access to the operating hospital's internal network; MEONA is operated exclusively within closed hospital networks without exposure to the public Internet, and where a hospital permits remote access to that network at all, it is only through the hospital's own remote-access infrastructure (e.g. VPN) under the hospital's control. The message contains only the recipient, subject and text entered by the user; no data of other users or patients is disclosed. Mesalvo is not aware of any exploitation outside the reported security test.
This issue affects MEONA Client and MEONA Server in versions 2024.10, 2025.04 (before 2025.04.24) and 2026.03 (before 2026.03.02). MEONA 2025.04.24 and 2026.03.02 (planned Q4 2026) enforce the configured recipient address on the server. Operators can restrict at their mail relay which recipients the MEONA sender address may reach.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
MEONA 2025.04.24 and 2026.03.02 (planned Q4 2026) enforce the configured recipient address on the MEONA Server and ignore any client-supplied recipient.
Vendor Workaround
Operators can restrict, at their mail relay, the recipients that the MEONA sender address (e.g. noreply-meona-…) may reach to the configured feedback mailbox, or to internal domains, and monitor messages from that sender address to other recipients. Details: Mesalvo Security Advisory MSA-2026-005.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mesalvo.com/en/vdp/advisories/msa-2026-005.pdf |
|
Fri, 25 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 25 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. | Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the server. The feedback function is available only in the MEONA administration area, which requires one of the administrative roles ADMINISTRATOR, SUPERADMINISTRATOR or TYPIST (catalogue editing), or the PHARMACIST role holding the PHARMACY_ADMINISTRATOR right, assigned explicitly by the operating hospital's administrators. Such a user who modifies the client request can cause the MEONA Server to send a message with content of the user's choosing, from the sender address configured on the server, to a recipient of the user's choosing, within the limits permitted by the operator's mail relay. The message can be used for social engineering because it appears to originate from an internal hospital system. Exploitation requires a MEONA account with one of the administrative roles named above and access to the operating hospital's internal network; MEONA is operated exclusively within closed hospital networks without exposure to the public Internet, and where a hospital permits remote access to that network at all, it is only through the hospital's own remote-access infrastructure (e.g. VPN) under the hospital's control. The message contains only the recipient, subject and text entered by the user; no data of other users or patients is disclosed. Mesalvo is not aware of any exploitation outside the reported security test. This issue affects MEONA Client and MEONA Server in versions 2024.10, 2025.04 (before 2025.04.24) and 2026.03 (before 2026.03.02). MEONA 2025.04.24 and 2026.03.02 (planned Q4 2026) enforce the configured recipient address on the server. Operators can restrict at their mail relay which recipients the MEONA sender address may reach. |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 21 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mesalvo
Mesalvo meona Client Launcher Component Mesalvo meona Server Component |
|
| Vendors & Products |
Mesalvo
Mesalvo meona Client Launcher Component Mesalvo meona Server Component |
Wed, 20 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Email Spoofing via Unverified Data in Mesalvo Meona Components |
Wed, 20 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-09-25T14:39:41.572Z
Reserved: 2026-02-03T07:24:49.548Z
Link: CVE-2026-25602
Updated: 2026-05-20T12:00:17.013Z
Status : Deferred
Published: 2026-05-20T11:16:26.313
Modified: 2026-09-25T15:17:54.327
Link: CVE-2026-25602
No data.
OpenCVE Enrichment
Updated: 2026-05-21T08:19:19Z
-
CWE-345
Insufficient Verification of Data Authenticity