Exploit Published for Fresh Cleo Harmony Vulnerability
PoC publicCleo HarmonyOur summary
A working exploit has been made available for CVE-2026-84115, a critical authentication bypass vulnerability affecting the Cleo Harmony file transfer application. The defect lies within the JWT refresh token logic, specifically allowing attackers to manipulate bearer tokens in HTTP headers to escalate privileges and bypass access controls. This poses a severe risk as organizations can suffer from persistent access or lateral movement across integrated systems. Users are urged to update to Cleo Harmony version 5.8.1.11 immediately, particularly because the product is a frequent target for ransomware groups such as Cl0p.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.