Junglewise Threat Intelligence

CVE-2026-84114: Cleo Harmony SAML authentication bypass via email manipulation

CVE-2026-84114 · Severity: medium · CVSS 6.3 · Published 2026-09-01

Executive brief

Cleo Harmony is a data integration and managed file transfer platform used by enterprises to securely exchange files. A flaw in its SAML authentication component allows attackers to bypass authentication by manipulating the email argument, enabling unauthorized access to the system without valid credentials. This could lead to unauthorized access to sensitive data and business operations.

Technical details

The vulnerability exists in the LocalUserUtil.getNativeUserByAssertions function within the SAML Authentication component of Cleo Harmony. The function improperly handles manipulation of the Email parameter in SAML assertions, resulting in an authentication bypass. The attack is remotely exploitable without requiring prior authentication or special privileges. An attacker can craft malicious SAML assertions with manipulated email values to authenticate as arbitrary users. The vendor has released version 5.8.1.11 which addresses this issue.

Affected products

  • Cleo Harmony up to 5.8.1.10

Timeline

  • 2026-09-01: disclosed: Public disclosure on NVD
  • 2026-09-01: patched: Fix available in version 5.8.1.11

References