Crypto Ticker:
sysadmin from Cyber Security News

Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token

Guru Baran
Sep 2, 2026 at 13:09
8 Views
0 Comments
Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token

A newly disclosed vulnerability in Cleo Harmony, a widely deployed managed file transfer and integration platform, is putting enterprise networks at risk after security researchers confirmed that remote attackers can escalate privileges by tampering with the software’s JWT refresh token mechanism. Tracked as CVE-2026-84115 and rated 8.3 (High) on the CVSS scale, the flaw affects all Cleo Harmony builds up to version 5.8.1.10, and a working public exploit is already circulating, raising the urgency for organizations to act quickly. The vulnerability lives inside the JWT Refresh Token Handler component, specifically in an unidentified function tied to the /api/connections endpoint. At the heart of the issue is improper handling...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!