Cleo Harmony customers should urgently patch CVE-2026-84115, a fresh authentication bypass flaw in the JWT refresh token logic that can let remote attackers elevate privileges through argument bearer manipulation. An exploit is already available, and the issue could be used for persistent access, lateral movement, and attacks on organizations using Cleo Harmony. #CleoHarmony #CVE-2026-84115 #Cl0p #WatchTowr
Keypoints
- CVE-2026-84115 affects Cleo Harmony and enables authentication bypass.
- The flaw is tied to JWT refresh token logic in the /api/connections endpoint.
- Attackers can manipulate HTTP header arguments to bypass access controls.
- An exploit has been released, raising the risk of real-world attacks.
- Cleo Harmony version 5.8.1.11 fixes the vulnerability and should be installed immediately.
Read More: https://www.securityweek.com/exploit-published-for-fresh-cleo-harmony-vulnerability/