Working Exploit Published for Cleo Harmony Flaw That Ransomware Gangs Already Love
A newly discovered flaw in the Cleo Harmony file-transfer application lets attackers break in and take control without a password. A working exploit is already public, and Cl0p used a different Cleo bug to hit major organisations just months ago.

Key points
- CVE-2026-84115, a newly disclosed authentication bypass flaw in Cleo Harmony, lets remote attackers gain elevated access without valid credentials.
- A working exploit for the vulnerability is already publicly available, raising the risk for every organisation still running an unpatched version.
- Cleo Harmony version 5.8.1.11 fixes the flaw; all users should update immediately.
- Security firm WatchTowr, which independently reproduced the vulnerability, describes Cleo Harmony as "a favourite ransomware gang target".
- In late 2024, the Cl0p ransomware group exploited a separate Cleo product flaw to steal data from multiple large organisations.
A fresh security flaw in Cleo Harmony, a business application used to transfer files between companies, has a working exploit available online before most organisations have had a chance to patch it. The clock is ticking.
Cleo Harmony is specialist software that large companies use to send and receive files with suppliers, partners and customers. Think purchase orders, invoices, shipping records. It sits at the centre of many supply chains, which is exactly why criminals like it.
What is the vulnerability and how serious is it?
Serious enough to patch today. The flaw, tracked as CVE-2026-84115, is an authentication bypass, meaning attackers can skip the login process entirely and gain the same level of access as a legitimate administrator.
The weakness sits in Harmony's handling of JWT refresh tokens. A JWT, or JSON Web Token, is a small digital pass that software systems hand to a user after they log in, confirming who they are for future requests. Cleo Harmony's logic for refreshing those passes is flawed: an attacker can forge or tamper with the token and trick the system into granting elevated privileges, essentially impersonating a high-level user.
Once inside, attackers can lock in persistent access, promote their own permissions further, or move sideways into other systems connected to Harmony.
Security database VulnDB confirmed that a working exploit has been published. Attack surface management firm WatchTowr said on Tuesday it had independently reproduced the bug and urged organisations to react fast, noting Cleo products are "a favourite ransomware gang target".
| Detail | Info |
|---|---|
| CVE ID | CVE-2026-84115 |
| Affected software | Cleo Harmony (all versions before 5.8.1.11) |
| Fixed version | 5.8.1.11 |
| Exploit status | Publicly available |
| Attack type | Authentication bypass, privilege escalation |
Why does the ransomware history matter?
Because this is not the first time Cleo has been here. In late 2024, the Cl0p ransomware group, a prolific criminal organisation that locks victims' files and demands multi-million-dollar payments for their release, exploited a different Cleo product flaw to steal data from a string of large organisations. No ransom payment details from that campaign have been confirmed publicly, but Cl0p routinely demands seven-figure sums.
Cl0p's playbook is to find widely used file-transfer software, exploit a flaw quietly, and pull data from dozens of victims before anyone notices. Cleo Harmony sits in exactly that category of software.
What should organisations do right now?
Update to Cleo Harmony version 5.8.1.11 immediately. Cleo did not publish technical details in its own advisory, but the fix is confirmed in that release.
IT teams should also review access logs for Harmony's /api/connections endpoint for unusual requests, particularly any that involve malformed or repeated authentication headers sent from unfamiliar addresses.
If your business uses a partner or supplier that runs Cleo Harmony, it is reasonable to ask them directly whether they have patched. A breach on their side can expose your data too.



