PoC public Cleo Harmony auth-bypass Cleo privilege-escalation
Exploit Published for Fresh Cleo Harmony Vulnerability
CVE Tools coverage
A working exploit has been made available for CVE-2026-84115, a critical authentication bypass vulnerability affecting the Cleo Harmony file transfer application. The defect lies within the JWT refresh token logic, specifically allowing attackers to manipulate bearer tokens in HTTP headers to escalate privileges and bypass access controls. This poses a severe risk as organizations can suffer from persistent access or lateral movement across integrated systems. Users are urged to update to Cleo Harmony version 5.8.1.11 immediately, particularly because the product is a frequent target for ransomware groups such as Cl0p.