Kill Chains and Coffee

Command Execution on Cleo Harmony via SAML Bypass | Kill Chains and Coffee

Episode Summary

In the AI era, it’s critical to test your attack surface just like an adversary would. Identifying truly exploitable risk means chaining together all possible vulnerabilities, rather than stopping when you find one. In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin red team expert Ilyass El Hadi revisited a recent kill chain that led to an exploit of Cleo Harmony, a managed file transfer application used by thousands of organizations to exchange sensitive documents. The chain began with unauthenticated external access leading to self-registration on the IdP (Okta). The Armadin attacker found two key vulnerabilities. The first was SAML XML Signature Wrapping (XSW). Cleo verified one SAML assertion but consumed an attacker-injected one and the attacker ultimately gained access to live support ticket files and customer data. The second vulnerability was ‘cross-store identity confusion’, which escalated from forged low-privilege identity to full Cleo administration privileges. Chained together, these vulnerabilities culminated in Cleo Actions abuse, with admin access sufficient for OS command execution in a production environment with sensitive data that could have impacted multiple organizations. The vulnerabilities were tracked as CVE-2026-84114 and CVE-2026-84115, and have already been patched. For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify exploitable risk across your entire environment. Learn how at http://hyperattack.AI.

Episode Notes

In the AI era, it’s critical to test your attack surface just like an adversary would. Identifying truly exploitable risk means chaining together all possible vulnerabilities, rather than stopping when you find one.

In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin red team expert Ilyass El Hadi revisited a recent kill chain that led to an exploit of Cleo Harmony, a managed file transfer application used by thousands of organizations to exchange sensitive documents.

The chain began with unauthenticated external access leading to self-registration on the IdP (Okta). The Armadin attacker found two key vulnerabilities. The first was SAML XML Signature Wrapping (XSW). Cleo verified one SAML assertion but consumed an attacker-injected one and the attacker ultimately gained access to live support ticket files and customer data.

The second vulnerability was ‘cross-store identity confusion’, which escalated from forged low-privilege identity to full Cleo administration privileges. Chained together, these vulnerabilities culminated in Cleo Actions abuse, with admin access sufficient for OS command execution in a production environment with sensitive data that could have impacted multiple organizations.

The vulnerabilities were tracked as CVE-2026-84114 and CVE-2026-84115, and have already been patched.

For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify exploitable risk across your entire environment. Learn how at http://hyperattack.AI.

RESOURCES 
Companion Blog Post: https://www.armadin.com/blog-posts/compromising-cleo-harmony-a-saml-bypass-chain-to-arbitrary-code-execution
Armadin Offensive Security Platform: https://armadin.com/platform 
Request a Demo: https://www.armadin.com/request-a-demo

CONNECT WITH ARMADIN 
Website: https://armadin.com 
LinkedIn: https://www.linkedin.com/company/armadin 
Twitter/X: https://x.com/armadinsecurity