← Vulnerability feed

Vulnerability record · CVE-2024-50623 · published 28 October 2024

CVE-2024-50623: Cleo Harmony, VLTrader, LexiCom Unrestricted File Upload RCE

Cleo · Harmony

Cleo Harmony, VLTrader, and LexiCom before 5.8.0.21 allow unrestricted file upload and download, which can lead to remote code execution. The flaw is remotely reachable without authentication, making it a severe risk for internet-facing file transfer servers.

9.8 CVSS 3.1 Critical CISA KEV since 13 Dec 2024 Known ransomware use EPSS 99% · top 0.1% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
2References
31 Jul 2026Last modified by NVD

Description

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, active exploitation in CISA KEV with known ransomware use, and near-certain EPSS probability make this an urgent threat.

What it is

Cleo Harmony, VLTrader, and LexiCom before 5.8.0.21 allow unrestricted file upload and download, which can lead to remote code execution. The flaw is remotely reachable without authentication, making it a severe risk for internet-facing file transfer servers.

Impact

An unauthenticated attacker can upload and execute arbitrary files, gaining remote code execution on the affected server. This can lead to full system compromise, data theft, and deployment of ransomware.

Attack surface

The vulnerability is network-reachable (AV:N) with no authentication (PR:N) and no user interaction (UI:N), based on the CVSS vector. Any exposed Cleo Harmony, VLTrader, or LexiCom instance before 5.8.0.21 is potentially reachable.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2024-12-13 with known ransomware campaign use, and EPSS shows a 30-day probability of 0.98607 (99.9th percentile), indicating active exploitation.

What to do

  • Upgrade Cleo Harmony, VLTrader, and LexiCom to version 5.8.0.21 or later immediately.
  • If patching is not possible, follow CISA's required action to apply vendor mitigations or discontinue use of the product.
  • Restrict network access to Cleo file transfer services to trusted sources only.
  • Monitor for and block unauthorized file uploads to Cleo application directories.
  • Review systems for signs of compromise and isolate affected hosts if indicators are found.

Detection

  • Monitor for unexpected file creation or modification in Cleo web-accessible directories.
  • Inspect web server and application logs for suspicious POST requests or file upload attempts.
  • Use file integrity monitoring to alert on new executable files in Cleo installation paths.
  • Hunt for outbound connections or process execution spawned by Cleo services that are unusual.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-50623 to the Known Exploited Vulnerabilities catalog on 13 December 2024 as "Cleo Multiple Products Unrestricted File Upload Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 January 2025.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-50623 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-55956Cleo Harmony, VLTrader and LexiCom unauthenticated command injection via AutorunCleo Harmony, VLTrader and LexiCom before 5.8.0.24 allow an unauthenticated user to import and execute arbitrary Bash or PowerShell commands on the h…KEVEPSS 94%analysed9.8CVE-2021-33576Cleo lexicom path traversal vulnerabilityAn issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal …EPSS 1.5%5.3CVE-2021-33577Cleo lexicom vulnerabilityAn issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves (via encryption and signing …EPSS 0.59%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed10.0CVE-2026-48908SP Page Builder for Joomla unauthenticated arbitrary file upload RCESP Page Builder for Joomla permits unauthenticated users to upload arbitrary files, which can lead to upload and execution of PHP code. The flaw is a…KEVEPSS 89%analysed9.8CVE-2024-7399Samsung MagicINFO 9 Server path traversal allows arbitrary file writeSamsung MagicINFO 9 Server before version 21.1050 contains a path traversal flaw (CWE-22) that also enables unrestricted file upload (CWE-434), letti…KEVEPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2024-50623), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.