Cleo has identified an XML Signature Wrapping issue in SAML assertion processing (CVE-2026-84114) and an improper privilege management issue in refresh token handling (CVE-2026-84115).
Note: The vulnerability affects Cleo Harmony® and Cleo VLTrader for versions prior to
- Cleo Harmony® in versions prior to 5.8.1.11
- Cleo VLTrader® in versions prior to 5.8.1.11
About the vulnerability
An actor exploiting the CVE-2026-84114 can effectively elevate the permissions assigned to one SAML user to those assigned to another. An actor exploiting CVE-2026-84115 can convert the privileges of a Portal user to those of an Administrator, provided the Portal user and the Administrator share the same user ID.
By chaining two techniques together, an actor holding only a valid SAML-enabled account and who can guess at a valid Administrator user ID can elevate their privileges to those of the Administrator, potentially assuming full administrative control of the instance.
Customer Support Information
Support Coverage Notification
Effective immediately, Cleo is granting 24x7 customer support access and coverage to all Cleo customers regardless of support level to address all matters specific to this vulnerability.
New support request process for Incorrect Privilege Assignment and Management
To help ensure that your security needs are addressed promptly, we have implemented a new protocol for any support request (ticket creation or email) regarding this vulnerability.
To create new tickets:
- Select Support Security - Submit a Support Ticket form when submitting a request via Solution Center, or
- email Security-support@cleo.com and include "Critical Cleo Security" in the subject line.
This will help ensure correct priority and assignment of your ticket, and help the support team address your request.
Patch Path
Note: Upgrading is the only complete remediation.
Install the patch version 5.8.1.13
|
Harmony Version |
System Requirements & OS support |
|---|---|
| 5.8.1.13 | https://support.cleo.com/hc/en-us/articles/30601185467159-Cleo-Harmony-5-8-1-System-Requirements |
|
VLTrader Version |
System Requirements & OS support |
|---|---|
| 5.8.1.13 | https://support.cleo.com/hc/en-us/articles/30979504825239-Cleo-VLTrader-5-8-1-System-Requirements |
Cleo Harmony Links
https://portal.cleo.com/patch/harmony/5.8.1.13.zip
https://portal.cleo.com/patch/harmony/notes.txt
Cleo VLTrader Links
https://portal.cleo.com/patch/vltrader/5.8.1.13.zip
https://portal.cleo.com/patch/vltrader/notes.txt
To apply the patch:
- Copy to the patch to an accessible location on the server running Harmony/VLTrader.
- Stop the Harmony/VLTrader service/daemon.
-
From the command line within the Harmony/VLTrader install folder, run the following command:
Linux
./Harmonyc -i [PATH_TO_ZIP] -m./VLTraderc -i [PATH_TO_ZIP] -m
Windows
Harmonyc.exe -i [PATH_TO_ZIP] -mVLTraderc.exe -i [PATH_TO_ZIP] -m?
- Start the Harmony/VLTrader service/daemon.
Upgrade Path
Update to version 6
|
Harmony Version |
System Requirements & OS support |
|---|---|
| 6.0.0 | https://support.cleo.com/hc/en-us/articles/41414681009303-Cleo-Harmony-6-0-System-Requirements |
|
VLTrader Version |
System Requirements & OS support |
|---|---|
| 6.0.0 | https://support.cleo.com/hc/en-us/articles/41497547325591-Cleo-VLTrader-6-0-System-Requirements |
Compensating Controls
If you are unable to immediately upgrade to version 5.8.1.13 or later:
- Upgrading is the only complete remediation.
- Ensure that no Portal user IDs overlap with administrator user IDs.
- Disable Harmony's built-in default administrative user “Administrator” after confirming it is unused and that a non-SSO administrator account exists with a non-guessable username.
- Restrict access to the Portal.
Additional Resources
Comments
0 comments
Please sign in to leave a comment.