CVE-2026-22315
Summary
| CVE | CVE-2026-22315 |
|---|---|
| State | PUBLISHED |
| Assigner | ENISA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-20 11:16:26 UTC |
| Updated | 2026-05-20 14:03:10 UTC |
| Description | Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export of user data, including cleartext passwords, via the SQL editor. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. |
Risk And Classification
Primary CVSS: v3.1 7.2 HIGH from a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.000470000 probability, percentile 0.148930000 (date 2026-05-27)
Problem Types: CWE-266 | CWE-266 CWE-266: Incorrect Privilege Assignment
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | Secondary | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Mesalvo | Meona Client Launcher Component | affected 19.06.2020 15:11:49 custom | Not specified |
| CNA | Mesalvo | Meona Server Component | affected 2025.04 5+323020 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| seccore.at/blog/cves-meona | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | seccore.at | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.