logo

Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token

ID: ab4d7f2c-fcc3-56ae-a5ed-11b87244825b

STIX ID: report--ab4d7f2c-fcc3-56ae-a5ed-11b87244825b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-09-02

Date Updated: 2026-09-16

Author: Guru Baran

...
...

Cleo Harmony has a high-severity (CVSS 8.3) vulnerability (CVE-2026-84115) in its JWT refresh token handling that allows remote privilege escalation by manipulating Bearer tokens; a public exploit exists, affected versions are up to 5.8.1.10, and Cleo released a fix in 5.8.1.11 — organizations should patch immediately or apply recommended mitigations (input validation, WAF rules, and log monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.