Impact
A vulnerability exists in the Cleo Harmony 5.8.1.10 and earlier versions within the SAML Authentication component, specifically in the function LocalUserUtil.getNativeUserByAssertions. The function incorrectly handles an Email argument, allowing an attacker to supply a manipulated value that bypasses authentication checks. This flaw can be exploited to impersonate any user, effectively granting access to protected resources. The weakness corresponds to CWE-287, an improper authentication vulnerability.
Affected Systems
Systems affected by this vulnerability are those running Cleo Harmony software up to and including version 5.8.1.10. The vulnerability is present in the SAML Authentication component of the application, regardless of operating environment, as long as that version is deployed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact, and the EPSS score is unavailable, meaning there is no publicly available data on exploitation frequency. The vulnerability is not listed in CISA KEV, but the exploit has been publicly disclosed, and it can be performed remotely. The lack of an official workaround means administrators should prioritize patching, as no simple configuration change can fully mitigate the vulnerability.
OpenCVE Enrichment