PT-2026-84292 · Cleo · Cleo Harmony
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cleo Harmony versions 5.8.1.0 through 5.8.1.10
Description
An issue exists in the JWT (JSON Web Token) refresh token handler within the
/api/connections endpoint. A remote attacker can manipulate the Bearer argument in HTTP headers to bypass authorization controls and achieve improper privilege management, potentially escalating their privileges to administrative levels. This flaw allows unauthorized access to protected functionality and integrated external systems. The vulnerability has been reproduced by researchers, and an exploit is publicly available.Recommendations
Upgrade Cleo Harmony to version 5.8.1.11.
Restrict access to the
/api/connections endpoint to trusted networks to minimize the risk of exploitation.Exploit
Fix
LPE
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cleo Harmony