Securityweek
Critical Cleo Harmony Vulnerability Exploited
Article Content
A new authentication bypass vulnerability, tracked as CVE-2026-84115, has been discovered in the Cleo Harmony file transfer application. This flaw affects the JWT refresh token logic, allowing remote attackers to manipulate bearer tokens and elevate privileges. An exploit targeting this vulnerability has been publicly released, significantly increasing the risk for organizations using Cleo Harmony. The vulnerability was found in an unknown function within the '/api/connections' file. Cleo has released version 5.8.1.11 to address this issue, but details about the vulnerability were not provided in their advisory. Organizations are urged to update immediately, as the application is a known target for ransomware groups. WatchTowr has confirmed the vulnerability's reproduction and emphasized the urgency for a rapid response. The potential for persistent access and lateral movement within integrated systems raises the stakes for affected organizations.
Key Points: • CVE-2026-84115 allows privilege escalation via JWT token manipulation. • An exploit for this vulnerability has already been released publicly. • Cleo Harmony customers must update to version 5.8.1.11 immediately.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.