Skip to content
Activamente explotadaCVSS 9.9 · CRITICAL

CVE-2024-57726

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Ver en NVD

Análisis

SimpleHelp remote support software contains a critical vulnerability allowing low-privileged technicians to escalate privileges to server administrator via malicious API key creation. This flaw is currently being exploited in the wild according to CISA, and users should update to a patched version immediately.

Severidad

Puntaje: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): NVD-CWE-noinfoCWE-862

CISA KEV

Agregada al KEV: 2026-04-24
Fecha límite federal: 2026-05-08
Uso conocido en ransomware: Unknown
Acción requerida

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probabilidad de explotación (próx. 30 días): 0.4916 (49.2%)
Percentil: 97.8%
EPSS: 2026-05-08

Afecta

simple-help:simplehelp

Descripción técnica

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Publicada: 15/1/2025, 23:15:09
Última modificación: 24/4/2026, 19:26:52

Referencias

InicioEventosBlogRecursosEquipo