news.mlab.sh
Back to the feed
vulnerability

Exploit Published for Fresh Cleo Harmony Vulnerability

HighCVSS 8.3
Summary

A new exploit targeting a vulnerability in Cleo Harmony, a file transfer application, has been released, allowing attackers to bypass authentication and escalate privileges. This vulnerability, tracked as CVE-2026-84115, has been actively exploited by ransomware groups, including Cl0p, and requires immediate patching to prevent further attacks.

Organizations are urged to swiftly patch a critical authentication bypass vulnerability within Cleo Harmony, a file transfer application. The vulnerability, identified as CVE-2026-84115, resides in the JWT refresh token logic and allows remote attackers to elevate their privileges through manipulated HTTP headers. According to VulnDB, an exploit for this vulnerability has been publicly released, significantly increasing the risk of exploitation across all Cleo Harmony users.

Attackers can leverage this flaw by intercepting legitimate traffic or crafting new requests with malformed or replayed bearer tokens to bypass access controls and achieve privilege escalation. This could lead to persistent access, lateral movement to connected systems, and ultimately, a greater risk of data compromise. Cleo Harmony version 5.8.1.11 addressed the vulnerability, but due to the availability of a public exploit, rapid action is crucial.

WatchTowr, an attack surface management firm, highlighted Cleo Harmony’s popularity among ransomware gangs, citing the Cl0p ransomware group’s prior exploitation of a Cleo product vulnerability in late 2024 to steal data from major organizations. The firm has already reproduced the vulnerability, emphasizing the urgency of patching to mitigate the risk.

Read the full article at SecurityWeek