CVE-2026-84115 | Cleo Harmony up to 5.8.1.10 JWT Refresh Token /api/connections Bearer privileges management
A vulnerability classified as critical has been found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management.
This vulnerability is reported as CVE-2026-84115. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More