Vulnerability
Published 2026-09-01
Verified 2026-09-19

Cleo Harmony ≤5.8.1.10: JWT refresh authz flaw (CVE-2026-84115); public exploit

SecurityWeek (2 September 2026) reports CVE-2026-84115 in Cleo Harmony file-transfer: improper privilege management in the JWT refresh token handler on /api/connections, where manipulating the Bearer argument can let a remote attacker elevate privileges. VulDB (listed as CNA-style record in public mirrors) says builds through 5.8.1.10 are affected, a public exploit exists, and upgrading to 5.8.1.11 fixes it. Cleo's Harmony 5.8.1 release notes list 5.8.1.11 as a 15 May 2026 limited/restricted build and do not expand on this CVE in the public notes SecurityWeek also noted thin vendor detail. WatchTowr (quoted by SecurityWeek) has reproduced the issue and flags Harmony as a frequent ransomware target historically. This desk does not invent a CVSS beyond what secondary reporting attributes; Cyber Security News cites 8.3 High for the same CVE. Patch to 5.8.1.11 or later; hunt anomalous /api/connections auth traffic.

Product
Cleo Harmony
Versions
Affected through 5.8.1.10; fixed in 5.8.1.11 (per VulDB / SecurityWeek)
CVSS
8.3 (High) — as reported by Cyber Security News for CVE-2026-84115; confirm against your advisory feed
Exploited in Australia?
unknown
Patch to
5.8.1.11 or later; monitor /api/connections and JWT refresh anomalies

Primary: Cleo Harmony 5.8.1 release notes (5.8.1.11) · Vendor: Cleo (vendor release notes) · CVE: CVE-2026-84115 · SecurityWeek (2 Sep 2026)

vulnerabilities network