Skip to content
COOEY

FAIL › dossier

SimpleHelp

VENDOR

· dossier confidence 0%

SimpleHelp's remote support software is plagued by critical security flaws, including remote code execution, privilege escalation, and authentication bypasses. The company's track record shows a pattern of fundamental input validation and access control failures across its core product and authentication mechanisms.

PROFILE
Categoryremote-support-softwareWhat they doSimpleHelp provides remote support software for IT technicians to remotely access and manage client devices.
SECURITY POSTURE

SimpleHelp has a poor security posture, evidenced by a series of critical vulnerabilities in its core product and authentication flows over multiple years.

Notable failures
  • CVE-2024-57728: zip-slip RCE allowing arbitrary code execution by admins
  • CVE-2024-57726: privilege escalation via API key creation by low-privileged technicians
  • CVE-2024-57727: path traversal flaw allowing unauthenticated download of sensitive files
  • CVE-2026-48558: OIDC flow accepting unsigned tokens enabling credential forgery and MFA bypass
Patterns: repeated path traversal and zip-slip vulnerabilities; insufficient input validation in authentication flows; privilege escalation via API key misconfiguration
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2026-04-24 CVE-2024-57728 critical SimpleHelp's SimpleHelp product allows admin users to execute arbitrary code via a zip-slip path traversal vulnerability.
2026-04-24 CVE-2024-57728 critical SimpleHelp's SimpleHelp product allows admin users to execute arbitrary code via a zip-slip path traversal vulnerability.
2026-04-24 CVE-2024-57726 critical SimpleHelp allows low-privileged technicians to create API keys with server admin privileges, enabling privilege escalation.
2026-04-24 CVE-2024-57726 critical SimpleHelp allows low-privileged technicians to create API keys with server admin privileges, enabling privilege escalation.
2025-02-13 CVE-2024-57727 critical SimpleHelp remote support software suffered a critical path traversal flaw allowing unauthenticated attackers to download sensitive files like config and hashed passwords.
2025-02-13 CVE-2024-57727 critical SimpleHelp remote support software suffered a critical path traversal flaw allowing unauthenticated attackers to download sensitive files like config and hashed passwords.
2026-06-29 CVE-2026-48558 high SimpleHelp's OIDC authentication flow accepts unsigned tokens, allowing remote attackers to forge credentials and bypass MFA.
2026-06-29 CVE-2026-48558 high SimpleHelp's OIDC authentication flow accepts unsigned tokens, allowing remote attackers to forge credentials and bypass MFA.
Open questions: SimpleHelp's founding year and headquarters location · SimpleHelp's company size and ownership structure · SimpleHelp's official website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-26 04:22:48.603135+00:00