
A newly disclosed vulnerability in Cleo Harmony, a widely deployed managed file transfer and integration platform, is putting enterprise networks at risk after security researchers confirmed that remote attackers can escalate privileges by tampering with the software's JWT refresh token mechanism. Tracked as CVE-2026-84115 and rated 8.3 (High) on the CVSS scale, the flaw affects all Cleo Harmony builds up to version 5.8.1.10, and a working public exploit is already circulating, raising the urgency for organizations to act quickly.
The vulnerability lives inside the JWT Refresh Token Handler component, specifically in an unidentified function tied to the /api/connections endpoint. At the heart of the issue is improper handling of the Bearer argument passed in HTTP authorization headers. By crafting a manipulated Bearer token, an attacker can trick the application into granting elevated permissions that were never intended for their session.
Cleo Harmony Vulnerability Security analysts classify this weakness under CWE-269,…
➪ Continue reading the full article on cybersecuritynews.com









