PT-2026-84285 · Cleo · Cleo Harmony

·

CVE-2026-84114

·

Published

2026-09-01

·

Updated

2026-09-05

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cleo Harmony versions prior to 5.8.1.11
Description An issue exists in the SAML Authentication component where manipulation of the Email argument within the LocalUserUtil.getNativeUserByAssertions() function allows for improper authentication. This flaw can be exploited remotely.
Recommendations Update to version 5.8.1.11. Upgrade the SAML Authentication component.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84114

Affected Products

Cleo Harmony