Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cleo

Cleo Vendor Cyber Rating & Cyber Score

cleo.com

Cleo is a supply chain orchestration software company that connects, automates, and optimizes the critical processes that keep goods and data moving. Our solutions help companies of all sizes, from small and midsize businesses to global enterprises, become EDI compliant and connect with their trading partners through EDI, APIs, application integration (ERP, WMS, TMS, etc.), cloud-based solutions, and easy-to-use web portals. Customers can choose self-service, managed services, or a combination of both based on their business needs. With real-time visibility and control across partners, customers, marketplaces, and internal systems, Cleo uses AI-powered capabilities to help businesses onboard faster, modernize business processes, identify


Cleo A.I CyberSecurity Scoring

Cleo
Company Information
Website:https://www.cleo.com
Employees number:583
Number of followers:14,924
NAICS:5112
Industry Type:Software Development
Homepage:cleo.com
Cleo Risk Score (AI oriented)
Between 600 and 649
logo
CleoSoftware Development
Updated:
03/09/2026
634/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Cleo Global Score (TPRM)
xxxx
logo
CleoSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CleoPoor
Current Score
634Caa (POOR)
01000
3 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
638Before Incident
Vulnerability
01 Sep 2026Cleo
Cleo: CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk

Critical Privilege Escalation Vulnerability in Cleo Harmony (CVE-2026-84115)

634After Incident
CRITICAL-4
CLE1788431185
Critical Privilege Escalation Vulnerability in Cleo Harmony (CVE-2026-84115) Exposes Systems to Remote Exploitation A severe privilege-management vulnerability, tracked as CVE-2026-84115, has been identified in Cleo Harmony versions up to 5.8.1.10, affecting the platform’s JWT Refresh Token Handler and the `/api/connections` endpoint. Disclosed by MITRE on September 1, 2026, and classified by VulDB (VDB-397558) as a CWE-269 (Improper Privilege Management) flaw, the vulnerability carries a CVSS score of 8.3, indicating high severity. The flaw stems from an unknown function in the JWT Refresh Token Handler, where manipulation of the Bearer token argument in HTTP authorization headers can lead to authentication bypass. Attackers exploiting this weakness could escalate privileges, gaining unauthorized administrative access, viewing sensitive data, or disrupting integration workflows managed through Cleo Harmony. The vulnerability is remotely exploitable via network-based HTTP requests, increasing its risk profile particularly as a public exploit has been reported. Successful exploitation could compromise confidentiality, integrity, and availability of systems relying on Cleo Harmony for file transfers and API connectivity. Attackers may intercept legitimate traffic or forge requests using malformed or replayed bearer tokens, potentially enabling lateral movement across connected environments. Remediation requires upgrading to Cleo Harmony version 5.8.1.11 or later, which addresses the privilege-management flaw. While interim measures such as enhanced input validation and bearer token monitoring may reduce exposure, they do not substitute for patching, given the availability of a public exploit. The vulnerability has been assigned an EPSS score of 0.00284, reflecting its exploitability risk.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Sensitive data exposureSystems Affected: Cleo Harmony (versions up to 5.8.1.10)Operational Impact: Disruption of integration workflows
DATA BREACH
Type Of Data Compromised: Sensitive data, integration workflows dataSensitivity Of Data: High
AUGUST 2026
637Before Incident
JULY 2026
635Before Incident
JUNE 2026
633Before Incident
MAY 2026
628Before Incident
APRIL 2026
626Before Incident
MARCH 2026
626Before Incident
FEBRUARY 2026
623Before Incident
JANUARY 2026
621Before Incident
DECEMBER 2025
618Before Incident
NOVEMBER 2025
615Before Incident
OCTOBER 2025
613Before Incident
AUGUST 2025
717Before Incident
Ransomware
01 Aug 2025Cleo
Oracle

Clop Ransomware Exploits Oracle E-Business Suite Zero-Day (CVE-2025-61882) in Data Theft Attacks

604After Incident
CRITICAL-113
ORA1692116100725
The Clop ransomware gang exploited a critical zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS), specifically within the BI Publisher Integration component, to conduct data theft attacks since at least August 2025. The flaw allowed unauthenticated remote code execution (RCE) via a single HTTP request, enabling attackers to steal sensitive corporate documents from unpatched systems. Oracle patched the vulnerability in early October 2025, but not before Clop launched an extortion campaign, emailing executives at multiple victim organizations to demand ransoms in exchange for not leaking the stolen data.The attack leveraged a vulnerability chain exposed by leaked proof-of-concept (PoC) exploits from the Scattered Lapsus$ Hunters group, increasing the risk of further exploitation by other threat actors. Clop’s campaign mirrors past high-profile breaches, including MOVEit Transfer (2,770+ organizations affected), Accellion FTA, and GoAnywhere MFT, reinforcing its reputation for large-scale data theft via zero-days. Oracle urged immediate patching, warning that internet-exposed EBS applications remain prime targets. The U.S. State Department has even offered a $10 million reward for intelligence linking Clop to foreign state sponsorship, underscoring the attack’s severity.
INCIDENT DETAILS -
TYPE
Data TheftRansomware ExtortionZero-Day Exploitation
MOTIVATION
Financial Gain (Extortion)Data Theft for Leverage
IMPACT
Sensitive DocumentsPotentially PII or Corporate DataOracle E-Business Suite (EBS) with unpatched BI Publisher IntegrationHigh (due to extortion and potential data leaks)Potential (if PII was stolen)
DATA BREACH
Sensitive Corporate DocumentsPotentially PIIHigh (confidential business documents)Confirmed (by Clop for extortion)Possible (not explicitly confirmed)
OCTOBER 2022
755Before Incident
Breach
28 Oct 2022Cleo
Cleo Communications US, LLC

Cleo Communications US, LLC Data Breach

682After Incident
CRITICAL-73
CLE047080525
The Maine Office of the Attorney General reported that Cleo Communications US, LLC experienced an external system breach (hacking) that began on October 28, 2022, and was discovered on February 8, 2023. Approximately 644 individuals were affected, including one Maine resident, and personal information, including Social Security numbers, may have been exposed. Written notices were sent on April 14, 2023, and credit monitoring and identity restoration services were offered for 24 months.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security numbers
DATA BREACH
Social Security numbersSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Cleo ?
?
What was Cleo's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Cleo's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Cleo's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Cleo's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Cleo's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Cleo's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Cleo's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Cleo's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Cleo's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Cleo's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Cleo's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Cleo's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Cleo ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Cleo's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Cleo Cyber Scoring History | Rankiteo