CVE-2026-84114 | Cleo Harmony up to 5.8.1.10 SAML Authentication LocalUserUtil.getNativeUserByAssertions Email improper authentication
A vulnerability described as critical has been identified in Cleo Harmony up to 5.8.1.10. Impacted is the function LocalUserUtil.getNativeUserByAssertions of the component SAML Authentication. Such manipulation of the argument Email leads to improper authentication.
This vulnerability is documented as CVE-2026-84114. The attack can be executed remotely. Additionally, an exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More