A public proof-of-concept exploit is available for CVE-2026-84115, a high-severity authentication-bypass and privilege-escalation flaw in Cleo Harmony's JWT refresh-token handling. Remote attackers can manipulate Bearer-token arguments sent to the /api/connections endpoint to bypass access controls and obtain elevated, potentially administrative, permissions; some attack paths may not require valid credentials.
The vulnerability affects Cleo Harmony versions through 5.8.1.10 and could expose managed file-transfer data or enable manipulation of connected integration workflows, particularly on internet-exposed deployments. Cleo fixed the issue in version 5.8.1.11; organizations should upgrade immediately and review API and token activity for suspicious requests while remediation is underway. No confirmed in-the-wild exploitation of this specific flaw was reported.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-84115, a critical improper privilege-management flaw in Cleo Harmony's JWT Refresh Token Handler, was disclosed and documented by MITRE. The flaw affects Harmony versions through 5.8.1.10 and can allow bearer-token manipulation at the /api/connections endpoint.
The Cl0p ransomware group exploited a vulnerability in a Cleo product and stole data from major organizations.
VulnDB reported that an exploit for CVE-2026-84115 was released, and other reports described a public proof-of-concept as circulating. The exploit uses manipulated, forged, or replayed Bearer tokens to bypass access controls and potentially gain elevated permissions remotely.
Cleo remediated the CVE-2026-84115 authentication-bypass and privilege-escalation flaw in Cleo Harmony version 5.8.1.11. The issue affects versions through 5.8.1.10 and involves JWT refresh-token handling at the /api/connections endpoint.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcethecyberexpress.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcevuldb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.