Advisories
MSA-2026-001: Role check of the MEONA Client and access to the
administration area (CVE-2026-0856)
For access to the administrative functions of the MEONA Client, the MEONA Server relies on the role
information supplied by the MEONA Client. A person who holds a valid MEONA user account, has access to
the hospital's internal network and is able to execute a modified copy of the MEONA Client can assert an
administrator role and access the administrative functions of the MEONA Client (admin panel) with regular
user credentials. MEONA is operated exclusively within closed hospital networks and is not exposed to the
public Internet.
Detailed Information are available here>>
MSA-2026-002: Legacy password storage methods for accounts predating
MEONA 2024.10 (CVE-2026-0857)
Since MEONA 2024.10 (June 2024) MEONA protects stored user passwords with Argon2, and every
password that is set or changed is stored with Argon2. Earlier versions protected passwords with SHA-1
(from October 2015) or stored them without protection (before). Passwords last set under an earlier version
keep the earlier method until they are changed, and a MEONA super administrator can read the stored value
of such accounts in the user administration. Only accounts managed locally in MEONA are affected; users
authenticated through the hospital's directory service have no password stored in MEONA. MEONA
2025.04.24 and 2026.03.02 remove the legacy methods, force a new password for every affected account
and stop displaying stored values.
Detailed Information are available here>>
MSA-2026-003: Scripting and Spring XML configuration functions in MEONA
administration (CVE-2026-22314)
MEONA offers administrators documented functions for customer-specific customisation: form scripting,
report scripting and Spring.NET XML content configuration. Scripts and configurations defined with these
functions are executed by the MEONA Client on the workstations of the users who open the affected forms,
reports or profiles. The functions are restricted to holders of dedicated administrative permissions that the
operating hospital assigns. A security test reported them as a code-injection vulnerability after reaching them
with a regular account through CVE-2026-0856. Mesalvo considers the functions intended administrative
functionality and has requested correction of the CVE record. This advisory explains what the functions do,
who can use them and how operators should govern them.
Detailed Information are available here>>
MSA-2026-004: Administrative SQL query tool in MEONA and SQL Server
hardening (CVE-2026-22315)
MEONA provides administrators with a documented SQL query tool ("Spezielle Reports") for preparing
report data directly from the MEONA database. The tool is restricted to holders of the super-administrator-
level permission REPORT_GLOBAL, which the operating hospital assigns. A security test reported the tool
as a vulnerability because, in the tested installation, the exported user table contained passwords stored with
legacy methods (CVE-2026-0857), and because the SQL Server instance allowed NTLM relay through
extended stored procedures. Mesalvo considers the tool intended administrative functionality, treats the
readable passwords under CVE-2026-0857, and addresses the SQL Server configuration through the
hardening guidance below.
Detailed Information are availablehere>>
MSA-2026-005: Client-supplied recipient address in the MEONA feedback
function (CVE-2026-25602)
The MEONA feedback function in the administration area lets users with an administrative role send a
feedback report by e-mail to a configured mailbox. The recipient address is transmitted by the MEONA
Client, and the MEONA Server uses the transmitted address. Such a user who modifies the request can
have the server send a message with content of their choosing, from the internal MEONA sender address, to
a recipient of their choosing, within the limits of the hospital's mail relay. Such a message can be used for
social engineering because it appears to come from an internal system. MEONA will use the configured
recipient address on the server side; until then operators can restrict the MEONA sender address at their
mail relay.
Detailed Information are available here>>