A vulnerability was found in Ylianst MeshCentral 1.1.21 and classified as problematic. The affected element is the function
CheckWebServerOriginName of the file webserver.js of the component WebSocket Endpoint. Such manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is uniquely identified as CVE-2026-66420. The attack can be launched remotely. No exploit exists.