Impact
The vulnerability is an improper access control flaw that allows a standard authenticated user to reach the Mesalvo Meona admin interface. This grants the user elevated privileges, potentially compromising system configuration, data integrity, and security settings. The weakness maps to CWE-284 and presents a direct path to unauthorized administration.
Affected Systems
Affected vendors are Mesalvo. The Meona Client Launcher Component is vulnerable through version 19.06.2020, while the Meona Server Component remains vulnerable through 2025.04. Administrators should verify the deployed component versions against these dates.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity vulnerability. No EPSS score is available, and the issue is not currently listed in the CISA KEV catalog, suggesting limited public exploitation data. The likely attack vector requires the attacker to already have a valid user account or local system access; from that position, they can navigate to the admin panel without further authentication, making the flaw readily exploitable in environments with broad user coverage.
OpenCVE Enrichment