Vulnerability record · CVE-2024-57726 · published 15 January 2025
CVE-2024-57726: SimpleHelp missing authorization lets low-privilege technicians escalate to admin
Simple Help · Simplehelp
SimpleHelp remote support software v5.5.7 and earlier fails to properly authorize API key creation, allowing low-privilege technicians to mint API keys with excessive permissions. Those keys can then be used to escalate to the server admin role. Because SimpleHelp is remote support software, compromise of the server can expose managed endpoints and sessions.
Description
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.9, active exploitation per KEV with ransomware use, and a high EPSS score make this an urgent patch-first issue.
What it is
SimpleHelp remote support software v5.5.7 and earlier fails to properly authorize API key creation, allowing low-privilege technicians to mint API keys with excessive permissions. Those keys can then be used to escalate to the server admin role. Because SimpleHelp is remote support software, compromise of the server can expose managed endpoints and sessions.
Impact
An attacker holding a low-privilege technician account gains server admin privileges, giving full control over the SimpleHelp server and, by extension, the endpoints and sessions it manages.
Attack surface
Reachable over the network via the SimpleHelp server interface (AV:N, AC:L). It requires an authenticated low-privilege technician account (PR:L) and no user interaction (UI:N).
Exploitation
Listed in CISA KEV with a due date of 2026-05-08 and flagged for known ransomware campaign use, and EPSS is 0.666 (99.2nd percentile), indicating active exploitation. Reference tags include a vendor release note, third-party advisories and a Microsoft threat-intelligence blog.
What to do
- Upgrade SimpleHelp to a version later than 5.5.7 per the vendor security advisory.
- If patching is not immediately possible, restrict network access to the SimpleHelp server and follow the vendor's mitigation guidance or discontinue use.
- Audit and remove any API keys created by low-privilege technician accounts, and review technician account permissions.
- Apply BOD 22-01 guidance for cloud services and treat the server as compromised if unauthorized admin activity is found.
- Rotate credentials and secrets for the SimpleHelp server and any integrated systems.
Detection
- Monitor SimpleHelp logs for API key creation events initiated by low-privilege technician accounts.
- Alert on privilege changes or new admin-role assignments on the SimpleHelp server.
- Hunt for anomalous API key usage, especially keys with elevated permissions or unusual source IPs.
- Correlate SimpleHelp server activity with endpoint management actions that follow shortly after API key creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-57726 to the Known Exploited Vulnerabilities catalog on 24 April 2026 as "SimpleHelp Missing Authorization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 8 May 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-57726 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-57726), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.