Junglewise Threat Intelligence

CVE-2026-84115: Cleo Harmony JWT privilege escalation in refresh token handler

CVE-2026-84115 · Severity: high · CVSS 8.3 · Published 2026-09-01

Executive brief

Cleo Harmony is a managed file transfer platform used for secure data exchange across enterprises. A vulnerability in the JWT refresh token handler allows remote attackers to manipulate authentication credentials, leading to unauthorized privilege escalation without requiring legitimate user credentials. This could enable attackers to gain administrative access and compromise sensitive file transfer operations.

Technical details

A privilege management flaw exists in the JWT Refresh Token Handler component of Cleo Harmony, specifically in the /api/connections endpoint. The vulnerability stems from improper validation of the Bearer token argument, allowing an attacker to manipulate JWT credentials to escalate privileges. The attack is network-accessible and does not require prior authentication or user interaction. Successful exploitation enables an unauthenticated remote attacker to gain elevated privileges on the system. The vulnerability is fixed in version 5.8.1.11 and later.

Affected products

  • Cleo Harmony up to 5.8.1.10

Timeline

  • 2026-09-01: disclosed

References