Skip to content
Actively exploitedCVSS 9.9 · CRITICAL

CVE-2024-57726

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

View on NVD

Analysis

SimpleHelp remote support software contains a critical vulnerability allowing low-privileged technicians to escalate privileges to server administrator via malicious API key creation. This flaw is currently being exploited in the wild according to CISA, and users should update to a patched version immediately.

Severity

Score: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): NVD-CWE-noinfoCWE-862

CISA KEV

Added to KEV: 2026-04-24
Federal patch deadline: 2026-05-08
Known ransomware use: Unknown
Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probability of exploitation (next 30 days): 0.4916 (49.2%)
Percentile: 97.8%
EPSS: 2026-05-08

Affects

simple-help:simplehelp

Technical description

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Published: 1/15/2025, 11:15:09 PM
Last modified: 4/24/2026, 7:26:52 PM

References

HomeEventsBlogResourcesTeam