CVE-2024-57726

CRITICAL KEV RANSOMWARE

Simple-help Simplehelp < 5.5.8 - Missing Authorization

Title source: rule

Description

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Scores

CVSS v3 9.9
EPSS 0.0031
EPSS Percentile 54.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2026-04-24
VulnCheck KEV 2025-04-17
Ransomware Use Confirmed
CWE
CWE-862
Status published
Products (1)
simple-help/simplehelp < 5.5.8
Published Jan 15, 2025
KEV Added Apr 24, 2026
Tracked Since Feb 18, 2026