Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony.
Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument bearer manipulation.
The flaw was discovered in an unknown function in the file ‘/api/connections’. An attacker could craft a malicious payload that tampers with the arguments in HTTP headers, bypassing access controls and leading to privilege escalation.
According to VulnDB, an exploit targeting the bug has been released, which significantly increases the risk of exploitation against all organizations that use Cleo Harmony.
“The exploitation strategy typically involves intercepting legitimate traffic or forging new requests where the JWT refresh token logic is bypassed through malformed or replayed bearer tokens,” VulnDB notes.
Attackers could exploit the issue to maintain persistent access, elevate their privileges, or move laterally to other systems that Cleo Harmony integrates with, it says.
The vulnerability was addressed in Cleo Harmony version 5.8.1.11, but Cleo refrained from sharing any details on the security defect in its advisory.
Cleo Harmony customers should update their instances as soon as possible. As attack surface management firm WatchTowr notes, the application is “a favorite ransomware gang target”.
In late 2024, the Cl0p ransomware group exploited a Cleo product vulnerability to steal data from major organizations.
“We’ve already reproduced the vulnerability,” WatchTowr said on Tuesday, urging rapid reaction.
Related: Chrome and Firefox Updates Patch Dozens of Vulnerabilities
Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
Related: Hackers Start Exploiting Critical Langflow Vulnerability
Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
