SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin…
| CVE ID | CVE-2024-57726 |
| Vendor | SimpleHelp |
| Affected Product | SimpleHelp |
| Vulnerability Type | Vulnerability |
| CVSS Score | 9.5 (CRITICAL) |
| Actively Exploited | ✅ Yes — CISA KEV Listed |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via cisa_kev) |
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.