Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token
ID: ab4d7f2c-fcc3-56ae-a5ed-11b87244825b
STIX ID: report--ab4d7f2c-fcc3-56ae-a5ed-11b87244825b
Feed Name: cybersecurityNews.com
Threat Score
Cleo Harmony has a high-severity (CVSS 8.3) vulnerability (CVE-2026-84115) in its JWT refresh token handling that allows remote privilege escalation by manipulating Bearer tokens; a public exploit exists, affected versions are up to 5.8.1.10, and Cleo released a fix in 5.8.1.11 — organizations should patch immediately or apply recommended mitigations (input validation, WAF rules, and log monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
