A new authentication bypass vulnerability, identified as CVE-2026-84115, has been discovered in the Cleo Harmony file transfer application, allowing remote attackers to manipulate JWT refresh tokens and elevate their privileges. This vulnerability, affecting the application's access control mechanisms, poses significant risks, including potential persistence and lateral movement across systems.
Cleo Harmony has addressed the issue in version 5.8.1.11, and organizations are urged to update promptly to mitigate the risk, especially following previous attacks by ransomware groups like Cl0p that exploited similar vulnerabilities. An exploit has already been released, heightening the urgency for customers to patch their systems.