Vulnerabilities & PatchesEmerging1 src
Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token
A newly disclosed vulnerability in Cleo Harmony , a widely deployed managed file transfer and integration platform, is putting enterprise networks at risk after security researchers confirmed that remote attackers can escalate privileges by tampering with the software’s JWT refresh token mechanism.
Tracked as CVE-2026-84115 and rated 8. 3 (High) on the CVSS scale, the flaw affects all Cleo Harmony builds up to version 5. 8. 1. 10, and a working public exploit is already circulating, raising the urgency for organizations to act quickly.
The vulnerability lives inside the JWT Refresh Token Handler component, specifically in an unidentified function tied to the /api/connections endpoint. At the heart of the issue is improper handling of the Bearer argument passed in HTTP authorization headers.