Vulnerabilities

Exploit Published for Fresh Cleo Harmony Vulnerability

The security defect allows remote attackers to bypass authentication through argument bearer manipulation.

File transfer vulnerability

Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony.

Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument bearer manipulation.

The flaw was discovered in an unknown function in the file ‘/api/connections’. An attacker could craft a malicious payload that tampers with the arguments in HTTP headers, bypassing access controls and leading to privilege escalation.

According to VulnDB, an exploit targeting the bug has been released, which significantly increases the risk of exploitation against all organizations that use Cleo Harmony.

“The exploitation strategy typically involves intercepting legitimate traffic or forging new requests where the JWT refresh token logic is bypassed through malformed or replayed bearer tokens,” VulnDB notes.

Attackers could exploit the issue to maintain persistent access, elevate their privileges, or move laterally to other systems that Cleo Harmony integrates with, it says.

Advertisement. Scroll to continue reading.

The vulnerability was addressed in Cleo Harmony version 5.8.1.11, but Cleo refrained from sharing any details on the security defect in its advisory.  

Cleo Harmony customers should update their instances as soon as possible. As attack surface management firm WatchTowr notes, the application is “a favorite ransomware gang target”.

In late 2024, the Cl0p ransomware group exploited a Cleo product vulnerability to steal data from major organizations. 

“We’ve already reproduced the vulnerability,” WatchTowr said on Tuesday, urging rapid reaction.

Related: Chrome and Firefox Updates Patch Dozens of Vulnerabilities

Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

Related: Hackers Start Exploiting Critical Langflow Vulnerability

Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

Related Content

ICS/OT

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

Vulnerabilities

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

Artificial Intelligence

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Vulnerabilities

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Vulnerabilities

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Endpoint Security

Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version