Status: KEV
| Advisory ID: CVE-2024-57726
Key Details
| CVE | CVE-2024-57726 |
| Vulnerability Name | SimpleHelp Missing Authorization Vulnerability |
| Affected products | SimpleHelp SimpleHelp |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-862 (Missing Authorization) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-04-24. |
| Exploitation prediction (EPSS) | 66.60% probability of exploitation in the next 30 days (99% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-05-08 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
What to Do
Monitor SimpleHelp 's web page for any future patch releases.
References
KEV Required Action