PoC exploit released for Cleo Harmony auth bypass CVE-2026-84115

A proof-of-concept exploit for Cleo Harmony auth bypass CVE-2026-84115 that manipulates JWT refresh tokens to escalate privileges has been published. Cleo patched the flaw in version 5.8.1.11.

A proof-of-concept exploit has been published for a Cleo Harmony authentication bypass tracked as CVE-2026-84115. The flaw affects JWT refresh token handling in an endpoint under /api/connections. Cleo released a patch in version 5.8.1.11, and customers are advised to apply the update immediately.

The vulnerability allows an attacker to alter bearer arguments in HTTP headers so the application bypasses access controls. An attacker can craft a payload that tampers with the arguments processed by the JWT refresh logic to elevate privileges or maintain persistent access.

VulnDB described the exploitation technique as intercepting legitimate traffic or forging requests in which malformed or replayed bearer tokens bypass the refresh token logic. The database said attackers could replay or forge tokens to gain higher privileges and move laterally to systems integrated with the file transfer platform.

WatchTowr reported it reproduced the flaw and urged rapid action. The firm noted the application is frequently targeted by ransomware groups and referenced a separate Cleo product that was exploited by the Cl0p group in late 2024 to steal data from large organizations.

Cleo’s advisory for release 5.8.1.11 did not include technical details about the defect. Because a proof-of-concept exploit is public, organizations running affected versions should update, monitor logs for signs of token tampering or replayed requests, and check for unexpected privilege changes.

Cleo Harmony is a managed file transfer solution used by enterprises to automate and secure data exchange with partners and internal systems. Any flaw in authentication or authorization can affect workflows that move sensitive files.

Articles by this author