CVE-2024-55956: Cleo Multiple Products Unauthenticated File Upload Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-12-17. EPSS: 94% chance of exploitation in the next 30 days.

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Affected products

  • Cleo Harmony: before 5.8.0.24 (fixed in 5.8.0.24)
  • Cleo Lexicom: before 5.8.0.24 (fixed in 5.8.0.24)
  • Cleo Vltrader: before 5.8.0.24 (fixed in 5.8.0.24)

Published 2024-12-13. Last modified 2026-08-05.