Skip to content
COOEY

EXPOSURES › CVE-2024-57726

CVE-2024-57726

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-57726 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildprivilege-escalationsupply-chain

SimpleHelp allows low-privileged technicians to create API keys with server admin privileges, enabling privilege escalation.

This missing authorization flaw lets unprivileged users bypass role restrictions to gain full server admin access, creating a critical supply-chain risk for DIB vendors relying on SimpleHelp's API infrastructure. Organizations must audit all API key generation workflows and enforce strict role-based access controls to prevent unauthorized privilege escalation.

Shame score — A critical privilege escalation vulnerability that allows low-privileged users to bypass authorization checks and gain server admin access represents a severe security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.