A Critical Cleo Harmony Vulnerability Has Been Exploited, Leaving Organizations Exposed to Privilege Elevation and Lateral Movement Attacks
Cleo Harmony users are facing a pressing security threat after a fresh authentication bypass vulnerability was discovered in the file transfer application. The vulnerability, tracked as CVE-2026-84115, allows remote attackers to manipulate JWT refresh tokens, granting them elevated privileges and enabling lateral movement attacks against integrated systems.
The issue affects organizations that use Cleo Harmony to manage file transfers, making it vulnerable to exploitation by malicious actors. An exploit targeting the bug has been released, significantly increasing the risk of successful attacks. According to VulnDB, attackers can bypass access controls by manipulating HTTP headers in legitimate traffic or forging new requests with malformed or replayed bearer tokens.
The vulnerability was patched in Cleo Harmony version 5.8.1.11, but the company chose not to disclose further details on the security defect in its advisory. As a result, customers are urged to update their instances as soon as possible. WatchTowr, an attack surface management firm, notes that Cleo Harmony is a favorite target of ransomware gangs, citing the recent Cl0p ransomware group’s exploitation of a Cleo product vulnerability.
The exploitation strategy involves intercepting legitimate traffic or forging new requests where the JWT refresh token logic is bypassed. Attackers could maintain persistent access, elevate their privileges, or move laterally to other systems integrated with Cleo Harmony. Given the risk of exploitation, organizations using Cleo Harmony should prioritize updating their instances to the patched version.
This vulnerability serves as a reminder that software applications are not immune to security flaws and require regular updates to stay secure. As seen in recent high-profile attacks, even well-established vendors can be targeted by malicious actors seeking to exploit vulnerabilities. Organizations must remain vigilant and proactive in addressing these threats, ensuring they have robust patching strategies and continuous monitoring in place.
In light of this incident, organizations using Cleo Harmony should take immediate action to protect themselves from potential exploitation. This includes applying the latest patches, implementing robust access controls, and regularly reviewing system logs for suspicious activity. By staying informed and proactive, businesses can mitigate the risk of successful attacks and maintain the security of their sensitive data.
Source: SecurityWeek — 2026-09-02