This pertains to a Path Traversal vulnerability – CVSS 4.0 High and an Authentication Bypass vulnerability – CVSS 4.0 Critical.
The vulnerability affects the following products:
| Path Traversal vulnerability – CVSS 4.0 High |
| Cleo Harmony |
|
| Cleo VLTrader |
|
| Cleo LexiCom |
|
| Authentication Bypass vulnerability –CVSS 4.0 Critical |
| Cleo Harmony |
|
| Cleo VLTrader |
|
| Cleo LexiCom |
Note: Cleo LexiCom is affected only when the licensed WebUI/WebBrowser functionality is enabled. |
Cleo strongly advises all customers to immediately patch their product(s) to version 5.8.1.15 or 6.0.0.1 to address the vulnerability.
Please visit Remediation: Path Traversal vulnerability – CVSS 4.0 High & Authentication Bypass vulnerability – CVSS 4.0 Critical to take immediate action.
Note: Official CVE identifiers have been requested and are not yet available. Cleo is working through the CVE assignment process and currently anticipates publishing the associated CVE information on or around October 6, 2026. We will provide the CVE identifiers once they have been officially assigned and published.
Comments
0 comments
Please sign in to leave a comment.