CVE-2024-57726

Analyzed
Published: 15 Jan 2025, 00:00
Last modified:25 Apr 2026, 03:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.9 CRITICAL
v3.1 (cve.org)
EPSS Score
0.31% LOW
0% probability 0.00%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 Jan 2025, 00:00
Published
Vulnerability first disclosed
24 Apr 2026, 00:00
Added to CISA KEV
SimpleHelp Missing Authorization Vulnerability
25 Apr 2026, 03:55
Last Modified
Vulnerability information updated
08 May 2026, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

CVSS Metrics

  • v3.1CRITICALScore: 9.9CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.31% Percentile: 54%

Techniques & Countermeasures

  • CWE-862Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Affected Systems

  • simple-helpsimplehelp

    < 5.5.8

References (5)