Exploit Published for Freshworks Cleo Harmony Authentication Bypass Vulnerability
A public exploit is now available for CVE-2026-84115, an authentication bypass vulnerability in Freshworks' Cleo Harmony file transfer software, increasing the risk for unpatched systems.

Organizations using Freshworks' Cleo Harmony file transfer application are urged to apply immediate patches following the public release of an exploit for a critical authentication bypass vulnerability. The flaw, tracked as CVE-2026-84115, affects the JWT refresh token logic and allows remote attackers to escalate privileges through argument manipulation.
The vulnerability was identified within an unspecified function located at the '/api/connections' endpoint. Attackers can exploit this by crafting malicious HTTP requests that tamper with arguments in the headers, effectively bypassing access controls and gaining elevated permissions. This bypass mechanism is a significant concern, as it can lead to unauthorized access to sensitive data and system functions.
According to VulnDB, the availability of a public exploit dramatically elevates the threat landscape for Cleo Harmony users. The exploitation strategy typically involves intercepting legitimate traffic or forging new requests where the JWT refresh token logic is circumvented by malformed or replayed bearer tokens. This makes it easier for less sophisticated attackers to leverage the vulnerability.
Successful exploitation could grant attackers persistent access to affected systems, enable them to elevate their privileges further, or facilitate lateral movement across integrated systems. Given Cleo Harmony's role in file transfers, a compromise could have far-reaching implications for data security and operational continuity.
Cleo Harmony has addressed this vulnerability in version 5.8.1.11. However, Cleo has not provided specific details regarding the security defect in its official advisory, underscoring the importance of proactive patching based on external reporting.
The urgency of patching is further emphasized by WatchTowr, an attack surface management firm, which notes that Cleo Harmony is a "favorite ransomware gang target." This historical targeting by ransomware groups means that unpatched instances are highly attractive to threat actors looking to disrupt operations and extort victims.
This incident echoes past attacks, such as the late 2024 compromise where the Cl0p ransomware group exploited a vulnerability in a Cleo product to exfiltrate data from numerous major organizations. The recurring targeting of Cleo products highlights a persistent risk for users of their software.
Given the active exploitation and the known threat actor interest in Cleo Harmony, customers are strongly advised to update their instances to version 5.8.1.11 or later as soon as possible to mitigate the risk of compromise. WatchTowr has confirmed reproducing the vulnerability, reinforcing the call for rapid remediation.
The new article provides further technical details on CVE-2026-84115, specifying that the vulnerability lies within the JWT Refresh Token Handler component and is exploitable via crafted HTTP requests to the /api/connections endpoint. It also highlights that successful exploitation could grant administrative control over the platform and notes that Cleo has released version 5.8.1.11 to address the improper privilege management.