Impact
A flaw in the JWT Refresh Token Handler of Cleo Harmony enables manipulation of the Bearer argument in the /api/connections endpoint, causing the system to incorrectly manage user privileges. The resulting remote vulnerability allows an attacker to issue crafted requests that override or elevate authorization levels, potentially granting unauthorized access to sensitive functions or data. The CVSS score of 6.9 indicates moderate severity.
Affected Systems
Cleo Harmony versions up to 5.8.1.10 are affected. The vulnerability is resolved in version 5.8.1.11, which introduces proper privilege checks for the Bearer parameter in the /api/connections endpoint.
Risk and Exploitability
The exploit is remotely possible and a public proof‑of‑concept is available, increasing the likelihood of real‑world attacks even though the EPSS score is not published. The CVSS score of 6.9 reflects the moderate risk, and the vulnerability is not currently listed in CISA’s KEV catalog. Given the remote exploitation and the availability of a public exploit, organizations should treat this as a high‑priority issue and move quickly to remediate.
OpenCVE Enrichment