---
id: CVE-2024-55956
title: >-
  In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before
  5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or
  PowerShell commands on the host system by leveraging the default settings of
  the Aut…
summary: >-
  In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before
  5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or
  PowerShell commands on the host system by leveraging the default settings of
  the Aut…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
  - CWE-77
vendor: cleo
product: harmony
affected:
  - harmony < 5.8.0.24
  - lexicom < 5.8.0.24
  - vltrader < 5.8.0.24
patched:
  - harmony 5.8.0.24
  - lexicom 5.8.0.24
  - vltrader 5.8.0.24
published: '2024-12-13'
updated: '2026-08-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-55956'
references:
  - url: >-
      https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Advisory-CVE-Pending
    label: cve@mitre.org
  - url: >-
      https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55956
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.93968
epssPercentile: 0.99843
kev: true
kevDateAdded: '2024-12-17'
kevDueDate: '2025-01-07'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-05T11:47:23.486Z'
exploits:
  metasploit:
    - exploit/multi/http/cleo_rce_cve_2024_55956
  nuclei:
    - CVE-2024-55956
  checkedAt: '2026-09-25T08:20:43.597Z'
exploitAvailable: true
---

## Overview

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

## Affected

- `harmony < 5.8.0.24`
- `lexicom < 5.8.0.24`
- `vltrader < 5.8.0.24`

## Remediation

Upgrade past the affected range:

- `harmony 5.8.0.24`
- `lexicom 5.8.0.24`
- `vltrader 5.8.0.24`
