Critical Cleo Harmony Vulnerability Exploited for Privilege Escalation

Critical Cleo Harmony Vulnerability Exploited for Privilege Escalation

First seen 2 Sep 2026, 14:13 UTC Feeds.FeedburnerSecurityweekCybersecuritynewssupport.cleo.comThecyberexpress+1 72.9

Article Content

Browse articles
ThreatCluster

A newly discovered authentication bypass vulnerability in Cleo Harmony, tracked as CVE-2026-84115, allows remote attackers to escalate privileges by manipulating JWT refresh tokens. The flaw, found in the '/api/connections' function, enables attackers to bypass access controls through crafted HTTP headers. An exploit has been published, increasing the urgency for organizations using Cleo Harmony to patch their systems. Cleo Harmony version 5.8.1.11 addresses this vulnerability, but details on the flaw were not disclosed in the advisory. Security experts warn that the application is a target for ransomware gangs, following previous incidents involving the Cl0p group. Organizations are advised to update their instances immediately to mitigate risks. The vulnerability has a CVSS score of 8.3, indicating a high severity level.

Key Points: • Cleo Harmony vulnerability CVE-2026-84115 allows privilege escalation via JWT manipulation. • An exploit for this vulnerability has been publicly released, increasing the risk for affected organizations. • Cleo Harmony version 5.8.1.11 addresses the vulnerability; immediate updates are recommended.

Ask AI about this cluster

Timeline

2026-01-23
CVE-2026-0768 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-82078 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-82329 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-81578 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84115 published
Cleo Harmony vulnerability allowing privilege escalation via JWT manipulation disclosed.
Securityweek
2026-09-01
Exploit released
An exploit targeting CVE-2026-84115 was published, raising the urgency for organizations to patch.
Securityweek
2026-09-01
CVE-2026-83549 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83548 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CISA KEV addition
CVE-2026-84115 added to CISA KEV catalog due to active exploitation risk.
Securityweek