Organizations are advised to immediately patch a new authentication bypass vulnerability affecting the Cleo Harmony file transfer application.
Tracked as CVE-2026-84115the security flaw affects the JWT refresh token logic and allows remote attackers to elevate their privileges by manipulating an argument carrier.
The vulnerability was detected in an unknown function in the file ‘/api/connections’. An attacker can create a malicious payload that forges arguments in HTTP headers, bypassing access controls and leading to privilege escalation.
According to VulnDB, an exploit targeting the bug has been released, greatly increasing the risk of exploitation against all organizations using Cleo Harmony.
“The exploitation strategy typically involves intercepting legitimate traffic or forging new requests, where the JWT refresh token logic is bypassed through malformed or replicated token carriers,” VulnDB notes.
Attackers could use the issue to maintain persistent access, elevate their privileges, or move laterally to other systems that Cleo Harmony integrates with, it said.
The vulnerability was fixed in version 5.8.1.11 of Cleo Harmony, but Cleo refrained from sharing any details about the security flaw in its consultative.
Cleo Harmony customers should update their instances as soon as possible. As attack surface management firm WatchTowr notes, the app is “a favorite target of ransomware gangs.”
In late 2024, the Cl0p ransomware group used a Cleo product vulnerability to steal data from large organizations.
“We have already reproduced the vulnerability,” WatchTowr said on Tuesday, calling for a quick response.
Related: Chrome and Firefox updates fix dozens of vulnerabilities
Related: SonicWall warns of two SMA1000 Zero-Days used in attacks
Related: Hackers are starting to exploit the critical Langflow vulnerability
Related: A critical vulnerability in JFrog Artifactory that is reported to be exploited in the wild