---
id: CVE-2026-22314
title: "Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems.\_This issue affects Meona Client Launcher C…"
summary: "Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems.\_This issue affects Meona Client Launcher C…"
severity: high
cvss: 7.9
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: Mesalvo
product: Meona Client Launcher Component
affected:
  - 'meona_client_launcher_component <= 19.06.2020 15:11:49'
  - meona_server_component <= 2025.04 5+323020
published: '2026-05-20'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T15:17:52.953'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22314'
references:
  - url: 'https://mesalvo.com/en/vdp/advisories/msa-2026-003.pdf'
    label: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
  - url: 'https://seccore.at/blog/cves-meona/'
    label: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
tags:
  - nvd
  - cve.org
epss: 0.00387
epssPercentile: 0.29997
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-05-20T12:29:31.474390Z'
ingestedAt: '2026-09-25T14:09:46.366Z'
---

## Overview

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
