CVE-2024-57726
CRITICAL KEV RANSOMWARESimple-help Simplehelp < 5.5.8 - Missing Authorization
Title source: ruleDescription
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
References (5)
Scores
CVSS v3
9.9
EPSS
0.0031
EPSS Percentile
54.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2026-04-24
VulnCheck KEV
2025-04-17
Ransomware Use
Confirmed
CWE
CWE-862
Status
published
Products (1)
simple-help/simplehelp
< 5.5.8
Published
Jan 15, 2025
KEV Added
Apr 24, 2026
Tracked Since
Feb 18, 2026