SecurityWeek said an exploit was published for Cleo Harmony CVE-2026-84115, a fresh authentication-bypass flaw in the file-transfer app that lets remote attackers raise privileges. Cleo fixed it in version 5.8.1.11.
The bug sits in the JWT refresh token logic. By manipulating how the bearer token is presented in the request, an attacker can make the app accept a refresh request it should reject, then act as a higher-privileged user. SecurityWeek and WatchTowr said exploit code is already public, and WatchTowr has reproduced the flaw.
For shops that use Cleo Harmony to move files or bridge into business systems, the exposure is not limited to the appliance itself. A foothold here can outlast the first login and carry into connected systems through the workflows Cleo brokers.