PT-2026-84292 · Cleo · Cleo Harmony

·

CVE-2026-84115

·

Published

2026-05-15

·

Updated

2026-09-07

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Cleo Harmony versions 5.8.1.0 through 5.8.1.10
Description An issue exists in the JWT (JSON Web Token) refresh token handler within the /api/connections endpoint. A remote attacker can manipulate the Bearer argument in HTTP headers to bypass authorization controls and achieve improper privilege management, potentially escalating their privileges to administrative levels. This flaw allows unauthorized access to protected functionality and integrated external systems. The vulnerability has been reproduced by researchers, and an exploit is publicly available.
Recommendations Upgrade Cleo Harmony to version 5.8.1.11. Restrict access to the /api/connections endpoint to trusted networks to minimize the risk of exploitation.

Exploit

Fix

LPE

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14239
CVE-2026-84115

Affected Products

Cleo Harmony