CVE-2026-25602
Summary
| CVE | CVE-2026-25602 |
|---|---|
| State | PUBLISHED |
| Assigner | ENISA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-20 11:16:26 UTC |
| Updated | 2026-05-20 14:03:10 UTC |
| Description | Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. |
Risk And Classification
Primary CVSS: v3.1 4.4 MEDIUM from a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS: 0.000070000 probability, percentile 0.005290000 (date 2026-05-27)
Problem Types: CWE-345 | CWE-345 CWE-345: Insufficient Verification of Data Authenticity
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | Secondary | 4.4 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| 3.1 | CNA | CVSS | 4.4 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Mesalvo | Meona Client Launcher Component | affected 19.06.2020 15:11:49 custom | Not specified |
| CNA | Mesalvo | Meona Server Component | affected 2025.04 5+323020 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| seccore.at/blog/cves-meona | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | seccore.at | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.