Critical Privilege Escalation Vulnerability in Cleo Harmony (CVE-2026-84115) Exposes Systems to Remote Exploitation
A severe privilege-management vulnerability, tracked as CVE-2026-84115, has been identified in Cleo Harmony versions up to 5.8.1.10, affecting the platform’s JWT Refresh Token Handler and the /api/connections endpoint. Disclosed by MITRE on September 1, 2026, and classified by VulDB (VDB-397558) as a CWE-269 (Improper Privilege Management) flaw, the vulnerability carries a CVSS score of 8.3, indicating high severity.
The flaw stems from an unknown function in the JWT Refresh Token Handler, where manipulation of the Bearer token argument in HTTP authorization headers can lead to authentication bypass. Attackers exploiting this weakness could escalate privileges, gaining unauthorized administrative access, viewing sensitive data, or disrupting integration workflows managed through Cleo Harmony. The vulnerability is remotely exploitable via network-based HTTP requests, increasing its risk profile particularly as a public exploit has been reported.
Successful exploitation could compromise confidentiality, integrity, and availability of systems relying on Cleo Harmony for file transfers and API connectivity. Attackers may intercept legitimate traffic or forge requests using malformed or replayed bearer tokens, potentially enabling lateral movement across connected environments.
Remediation requires upgrading to Cleo Harmony version 5.8.1.11 or later, which addresses the privilege-management flaw. While interim measures such as enhanced input validation and bearer token monitoring may reduce exposure, they do not substitute for patching, given the availability of a public exploit. The vulnerability has been assigned an EPSS score of 0.00284, reflecting its exploitability risk.
Source: https://thecyberexpress.com/cve-2026-84115-cleo-harmony-jwt-refresh-token/
Cleo cybersecurity rating report: https://www.rankiteo.com/company/cleo-communications
"id": "CLE1788431185",
"linkid": "cleo-communications",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Integration Platform',
'name': 'Cleo Harmony',
'type': 'Software'}],
'attack_vector': 'Network',
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Sensitive data, integration '
'workflows data'},
'date_publicly_disclosed': '2026-09-01',
'description': 'A severe privilege-management vulnerability, tracked as '
'CVE-2026-84115, has been identified in Cleo Harmony versions '
'up to 5.8.1.10, affecting the platform’s JWT Refresh Token '
'Handler and the /api/connections endpoint. The flaw allows '
'attackers to manipulate the Bearer token argument in HTTP '
'authorization headers, leading to authentication bypass and '
'privilege escalation. Successful exploitation could '
'compromise confidentiality, integrity, and availability of '
'systems relying on Cleo Harmony for file transfers and API '
'connectivity.',
'impact': {'data_compromised': 'Sensitive data exposure',
'operational_impact': 'Disruption of integration workflows',
'systems_affected': 'Cleo Harmony (versions up to 5.8.1.10)'},
'post_incident_analysis': {'corrective_actions': 'Patch management, enhanced '
'input validation, bearer '
'token monitoring',
'root_causes': 'Improper privilege management in '
'JWT Refresh Token Handler'},
'recommendations': 'Upgrade to Cleo Harmony version 5.8.1.11 or later, '
'implement enhanced input validation, and monitor bearer '
'tokens for suspicious activity.',
'references': [{'source': 'MITRE'}, {'source': 'VulDB (VDB-397558)'}],
'response': {'containment_measures': 'Upgrade to Cleo Harmony version '
'5.8.1.11 or later',
'enhanced_monitoring': 'Bearer token monitoring',
'remediation_measures': 'Enhanced input validation, bearer token '
'monitoring'},
'title': 'Critical Privilege Escalation Vulnerability in Cleo Harmony '
'(CVE-2026-84115)',
'type': 'Privilege Escalation',
'vulnerability_exploited': 'CVE-2026-84115 (CWE-269: Improper Privilege '
'Management)'}