Cleo Harmony ≤5.8.1.10: JWT refresh authz flaw (CVE-2026-84115); public exploit
SecurityWeek (2 September 2026) reports CVE-2026-84115 in Cleo Harmony file-transfer: improper privilege management in the JWT refresh token handler on /api/connections, where manipulating the Bearer argument can let a remote attacker elevate privileges. VulDB (listed as CNA-style record in public mirrors) says builds through 5.8.1.10 are affected, a public exploit exists, and upgrading to 5.8.1.11 fixes it. Cleo's Harmony 5.8.1 release notes list 5.8.1.11 as a 15 May 2026 limited/restricted build and do not expand on this CVE in the public notes SecurityWeek also noted thin vendor detail. WatchTowr (quoted by SecurityWeek) has reproduced the issue and flags Harmony as a frequent ransomware target historically. This desk does not invent a CVSS beyond what secondary reporting attributes; Cyber Security News cites 8.3 High for the same CVE. Patch to 5.8.1.11 or later; hunt anomalous /api/connections auth traffic.
- Product
- Cleo Harmony
- Versions
- Affected through 5.8.1.10; fixed in 5.8.1.11 (per VulDB / SecurityWeek)
- CVSS
- 8.3 (High) — as reported by Cyber Security News for CVE-2026-84115; confirm against your advisory feed
- Exploited in Australia?
- unknown
- Patch to
- 5.8.1.11 or later; monitor /api/connections and JWT refresh anomalies
Primary: Cleo Harmony 5.8.1 release notes (5.8.1.11) · Vendor: Cleo (vendor release notes) · CVE: CVE-2026-84115 · SecurityWeek (2 Sep 2026)
