CVE-2026-0856
Deferred
Deferred - Pending Action
Improper Access Control in Meona Client Launcher and Server
Publication date: 2026-05-20
Last updated on: 2026-05-20
Assigner: ENISA
Description
Description
Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mesalvo | meona_client_launcher_component | to 19.06.2020 (exc) |
| mesalvo | meona_server_component | to 2025.04 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |