administrative functionality restricted to dedicated administrative
permissions assigned by the operating hospital; its use by a permission
holder is not a vulnerability. Unauthorised access to the functions is
addressed under CVE-2026-0856.
Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mesalvo.com/en/vdp/advisories/msa-2026-003.pdf |
|
Fri, 02 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Control of Code Generation in Mesalvo Meona Components Enables Remote Code Execution |
Thu, 01 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. | Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. |
Sat, 26 Sep 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Code Injection Vulnerability in Mesalvo Meona Components Allowing Remote Code Execution |
Fri, 25 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 25 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 25 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 21 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mesalvo
Mesalvo meona Client Launcher Component Mesalvo meona Server Component |
|
| Vendors & Products |
Mesalvo
Mesalvo meona Client Launcher Component Mesalvo meona Server Component |
Wed, 20 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Code Injection Vulnerability in Mesalvo Meona Components Allowing Remote Code Execution |
Wed, 20 May 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-10-01T19:31:41.782Z
Reserved: 2026-01-07T09:31:00.563Z
Link: CVE-2026-22314
Updated: 2026-05-20T12:30:06.197Z
Status : Deferred
Published: 2026-05-20T11:16:26.057
Modified: 2026-10-01T20:17:24.427
Link: CVE-2026-22314
No data.
OpenCVE Enrichment
Updated: 2026-10-02T00:00:15Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')