← Terug naar overzicht

A vulnerability was identified in Cleo Harmony versions up to 5.8.1.10 affecting the JWT Refresh Token Handler component at the /api/connections endpoint. The flaw involves improper privilege management triggered by manipulation of the Bearer argument, potentially allowing unauthorized privilege escalation. The vulnerability is remotely exploitable and a public exploit is available, raising the risk of active exploitation. Cleo has released version 5.8.1.11 to address the issue, and users are strongly advised to upgrade immediately. The vulnerability has been documented on NVD and VulDB, with multiple references available for technical details and release notes.

Affected products

  • Cleo Harmony up to 5.8.1.10

Related CVE's

  • CVE-2026-84115

Categories

  • Enterprise Applications
  • Identity & Access
  • Zero-Day Vulnerabilities