Cleo has identified an XML Signature Wrapping issue in SAML assertion processing (CVE-2026-84114) and an improper privilege management issue in refresh token handling (CVE-2026-84115).
The vulnerability affects the following products:
- Cleo Harmony® in versions prior to 5.8.1.11
- Cleo VLTrader® in versions prior to 5.8.1.11
Cleo strongly advises all customers immediately upgrade their product(s) to version 5.8.1.13 or later to address the vulnerability.
Please visit Improper Privilege Management Vulnerability (CVE-2026-84114 | CVE-2026-84115) to take immediate action.
Note: Customers on version 5.8.1.11 or later are not subject to the vulnerability.
Comments
0 comments
Please sign in to leave a comment.