Critical Cleo Harmony Vulnerability Exploited

Critical Cleo Harmony Vulnerability Exploited

First seen 2 Sep 2026, 14:13 UTC Feeds.FeedburnerSecurityweeksupport.cleo.comnvd.nist.gov 72.9

Article Content

Browse articles
ThreatCluster

A new authentication bypass vulnerability, tracked as CVE-2026-84115, has been discovered in the Cleo Harmony file transfer application. This flaw affects the JWT refresh token logic, allowing remote attackers to manipulate bearer tokens and elevate privileges. An exploit targeting this vulnerability has been publicly released, significantly increasing the risk for organizations using Cleo Harmony. The vulnerability was found in an unknown function within the '/api/connections' file. Cleo has released version 5.8.1.11 to address this issue, but details about the vulnerability were not provided in their advisory. Organizations are urged to update immediately, as the application is a known target for ransomware groups. WatchTowr has confirmed the vulnerability's reproduction and emphasized the urgency for a rapid response. The potential for persistent access and lateral movement within integrated systems raises the stakes for affected organizations.

Key Points: • CVE-2026-84115 allows privilege escalation via JWT token manipulation. • An exploit for this vulnerability has already been released publicly. • Cleo Harmony customers must update to version 5.8.1.11 immediately.

Timeline

2026-01-23
CVE-2026-0768 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-81578 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-82078 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-82329 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84115 published
Cleo Harmony's authentication bypass vulnerability was disclosed, impacting JWT refresh token logic.
Securityweek
2026-09-01
Exploit released
A proof-of-concept exploit targeting CVE-2026-84115 was made public, increasing risk for users.
Securityweek
2026-09-01
CVE-2026-83548 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83549 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
Cleo Harmony patch released
Cleo released version 5.8.1.11 to address the vulnerability, urging immediate updates for users.
Securityweek