CVE-2026-0856
Improper Access Control in Meona Client Launcher and Server
Publication date: 2026-05-20
Last updated on: 2026-05-20
Assigner: ENISA
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mesalvo | meona_client_launcher_component | to 19.06.2020 (exc) |
| mesalvo | meona_server_component | to 2025.04 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-0856 is an Improper Access Control vulnerability found in the Mesalvo Meona Client Launcher Component and the Mesalvo Meona Server Component. This flaw allows a normal user to gain unauthorized access to the admin panel, which should normally be restricted to administrators only.
How can this vulnerability impact me? :
This vulnerability can have a significant impact as it allows a normal user to access the admin panel without proper authorization. This could lead to unauthorized changes, data breaches, or disruption of services since the attacker gains high privileges (confidentiality, integrity, and availability are all highly impacted according to the CVSS score).