新たなCleo Harmonyの脆弱性、実証コードが公開

Image

ファイル転送アプリケーション「Cleo Harmony」に影響を及ぼす新たな認証バイパスの脆弱性が発見され、各組織に対して直ちにパッチを適用するよう勧告が出されています。

CVE-2026-84115として追跡されているこのセキュリティ上の欠陥は、JWTリフレッシュトークンのロジックに影響を及ぼすもので、リモートの攻撃者が引数のベアラー操作を通じて権限を昇格させることを可能にします。

この不具合は、ファイル「/api/connections」内の未特定の関数で発見されました。攻撃者はHTTPヘッダー内の引数を改ざんする悪意あるペイロードを作成することで、アクセス制御を回避し、権限昇格につなげることが可能です。

VulnDBによると、この不具合を標的とするエクスプロイトがすでに公開されており、Cleo Harmonyを利用するすべての組織にとって悪用のリスクが大幅に高まっているとしています。

「典型的な悪用手法としては、正規のトラフィックを傍受するか、あるいは不正な形式または再送されたベアラートークンによってJWTリフレッシュトークンのロジックを回避する新たなリクエストを偽造する手口が挙げられます」とVulnDBは指摘しています

攻撃者はこの問題を悪用することで、持続的なアクセスの維持、権限の昇格、あるいはCleo Harmonyと連携する他システムへの横展開を図る可能性があるとされています。

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert
insights.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

翻訳元: https://www.securityweek.com/exploit-published-for-fresh-cleo-harmony-vulnerability/

本記事は securityweek.com の記事を翻訳・要約したものです。