Junglewise Threat Intelligence

CVE-2024-57726: SimpleHelp privilege escalation via missing authorization in API key creation

CVE-2024-57726 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2026-04-24

Technologies: SimpleHelp. Vendors: Simplehelp.

Executive brief

SimpleHelp, a remote support and management platform, contains a security flaw that allows technicians with limited access to grant themselves full administrative control. By creating unauthorized API keys with elevated permissions, a low-privileged user can take over the entire server. This vulnerability has been actively exploited in the wild, potentially leading to full system compromise and deployment of ransomware.

Technical details

A missing authorization vulnerability (CWE-862) exists in SimpleHelp remote support software versions 5.5.7 and prior. The flaw allows an authenticated user with 'technician' level privileges to bypass intended access controls and generate API keys with permissions exceeding their own. These keys can then be leveraged to escalate privileges to the 'server admin' role. The attack is network-reachable and requires low complexity, though it does require valid technician credentials. This vulnerability is documented as being exploited in the wild by threat actors for ransomware operations. Users should update to version 5.5.8 or later to remediate the issue.

Affected products

  • SimpleHelp SimpleHelp Remote Support Software v5.5.7 and earlier

Timeline

  • 2025-01-15: disclosed: Initial CVE publication
  • 2025-01-16: patched: Vendor release notes for version 5.5.8+ address the issue
  • 2026-04-24: kev added: CISA added to Known Exploited Vulnerabilities catalog
  • 2026-04-24: exploited: Reports of use in Medusa ransomware operations

Related threats