


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh …
Published:
1 september 2026 om 00:00:00
Alert date:
1 september 2026 om 18:05:17
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Zero-Day Vulnerabilities
A vulnerability was identified in Cleo Harmony versions up to 5.8.1.10 affecting the JWT Refresh Token Handler component at the /api/connections endpoint. The flaw allows manipulation of the Bearer argument, leading to improper privilege management. The vulnerability is remotely exploitable and a public exploit has been released, increasing the risk of active exploitation. Affected users are advised to upgrade to version 5.8.1.11, which resolves the issue. The vulnerability has been assigned CVE-2026-84115 and is tracked by both NVD and VulDB.
Technical details
Mitigation steps:
Affected products:
Cleo Harmony up to 5.8.1.10
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84115
https://support.cleo.com/hc/en-us/articles/30258468834583-Cleo-Harmony-5-8-1-Release-Notes#Version58111
https://vuldb.com/cve/CVE-2026-84115
https://vuldb.com/submit/882468
https://vuldb.com/vuln/397558
https://vuldb.com/vuln/397558/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
