Skip to content
archivevulnerability · 03 Sep 2026 · 09:27 UTC

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk

VULNCVE-2026-84115source · THC

last 60 dispatches · spectrum

A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint. MITRE documented the issue on September 1, 2026, while VulDB classified it as a serious privilege-management vulnerability with a CVSS score of 8.3. CVE-2026-84115 Targets JWT Refresh Token Handler According to the vulnerability analysis , CVE-2026-84115 involves an unknown function within the JWT Refresh Token Handler component. …

CVE · detail
grounded ✓primary source ↗

loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected