← Vulnerability feed

Vulnerability record · CVE-2024-57726 · published 15 January 2025

CVE-2024-57726: SimpleHelp missing authorization lets low-privilege technicians escalate to admin

Simple Help · Simplehelp

SimpleHelp remote support software v5.5.7 and earlier fails to properly authorize API key creation, allowing low-privilege technicians to mint API keys with excessive permissions. Those keys can then be used to escalate to the server admin role. Because SimpleHelp is remote support software, compromise of the server can expose managed endpoints and sessions.

9.9 CVSS 3.1 Critical CISA KEV since 24 Apr 2026 Known ransomware use EPSS 67% · top 0.7% CWE-862 · Missing authorization
9.9CVSS 3.1 base score
67%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.9, active exploitation per KEV with ransomware use, and a high EPSS score make this an urgent patch-first issue.

What it is

SimpleHelp remote support software v5.5.7 and earlier fails to properly authorize API key creation, allowing low-privilege technicians to mint API keys with excessive permissions. Those keys can then be used to escalate to the server admin role. Because SimpleHelp is remote support software, compromise of the server can expose managed endpoints and sessions.

Impact

An attacker holding a low-privilege technician account gains server admin privileges, giving full control over the SimpleHelp server and, by extension, the endpoints and sessions it manages.

Attack surface

Reachable over the network via the SimpleHelp server interface (AV:N, AC:L). It requires an authenticated low-privilege technician account (PR:L) and no user interaction (UI:N).

Exploitation

Listed in CISA KEV with a due date of 2026-05-08 and flagged for known ransomware campaign use, and EPSS is 0.666 (99.2nd percentile), indicating active exploitation. Reference tags include a vendor release note, third-party advisories and a Microsoft threat-intelligence blog.

What to do

  • Upgrade SimpleHelp to a version later than 5.5.7 per the vendor security advisory.
  • If patching is not immediately possible, restrict network access to the SimpleHelp server and follow the vendor's mitigation guidance or discontinue use.
  • Audit and remove any API keys created by low-privilege technician accounts, and review technician account permissions.
  • Apply BOD 22-01 guidance for cloud services and treat the server as compromised if unauthorized admin activity is found.
  • Rotate credentials and secrets for the SimpleHelp server and any integrated systems.

Detection

  • Monitor SimpleHelp logs for API key creation events initiated by low-privilege technician accounts.
  • Alert on privilege changes or new admin-role assignments on the SimpleHelp server.
  • Hunt for anomalous API key usage, especially keys with elevated permissions or unusual source IPs.
  • Correlate SimpleHelp server activity with endpoint management actions that follow shortly after API key creation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-57726 to the Known Exploited Vulnerabilities catalog on 24 April 2026 as "SimpleHelp Missing Authorization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 8 May 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-57726 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2024-57726), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.