Exploit Published for Fresh Cleo Harmony Vulnerability
Exploit released for Fresh Cleo Harmony CVE-2026-84115, enabling authentication bypass and privilege escalation.
Summary
A critical authentication bypass vulnerability (CVE-2026-84115) in Cleo Harmony has a public exploit available, significantly increasing the risk of exploitation. Attackers can use argument bearer manipulation to bypass access controls, leading to privilege escalation and potential lateral movement. The vulnerability has been patched in version 5.8.1.11, and organizations are urged to update immediately, especially given Cleo Harmony's history as a target for ransomware groups like Cl0p.
Full text
Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony. Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument bearer manipulation. The flaw was discovered in an unknown function in the file ‘/api/connections’. An attacker could craft a malicious payload that tampers with the arguments in HTTP headers, bypassing access controls and leading to privilege escalation. According to VulnDB, an exploit targeting the bug has been released, which significantly increases the risk of exploitation against all organizations that use Cleo Harmony. “The exploitation strategy typically involves intercepting legitimate traffic or forging new requests where the JWT refresh token logic is bypassed through malformed or replayed bearer tokens,” VulnDB notes. Attackers could exploit the issue to maintain persistent access, elevate their privileges, or move laterally to other systems that Cleo Harmony integrates with, it says.Advertisement. Scroll to continue reading. The vulnerability was addressed in Cleo Harmony version 5.8.1.11, but Cleo refrained from sharing any details on the security defect in its advisory. Cleo Harmony customers should update their instances as soon as possible. As attack surface management firm WatchTowr notes, the application is “a favorite ransomware gang target”. In late 2024, the Cl0p ransomware group exploited a Cleo product vulnerability to steal data from major organizations. “We’ve already reproduced the vulnerability,” WatchTowr said on Tuesday, urging rapid reaction. Related: Chrome and Firefox Updates Patch Dozens of Vulnerabilities Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Related: Hackers Start Exploiting Critical Langflow Vulnerability Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Hackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM JackpottingRansomware Gang Claims Nutex Health Data Breach9.5 Million Impacted by Aesto Health Data BreachWatchGuard Patches Critical VulnerabilitiesServiceNow Patches 3 Critical Code Injection VulnerabilitiesMcKesson Confirms Data Breach as Attacker Deadline LoomsCritical Ruby on Rails Vulnerability in Attackers’ Crosshairs Latest News Rockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsAnthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsMalicious Virtualizor Update Served via BGP HijackingOpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-DaysChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet DisruptedSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksPalo Alto Networks Acquires AI Agent Platform Console Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-84115