Improper Authentication Vulnerability in Cleo Harmony SAML Authentication
CVE-2026-84114

5.3MEDIUM

Key Information:

Vendor

Cleo

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84114?

A security flaw resides within Cleo Harmony's SAML Authentication feature, specifically affecting the LocalUserUtil.getNativeUserByAssertions function. This vulnerability allows attackers to manipulate the email argument, potentially leading to unauthorized access. The issue can be triggered remotely, thus posing a significant risk to affected users. To mitigate this threat, it is essential for users to upgrade to the latest version 5.8.1.11, which addresses this vulnerability and enhances the overall security of the product.

Affected Version(s)

Harmony 5.8.1.0

Harmony 5.8.1.1

Harmony 5.8.1.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ilyass-armadin (VulDB User)
.