Consumer Alerts Tracker
CISA KEV

SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Official details

Category
Known exploited vulnerability
Classification
Ransomware use: Known
Company or vendor
SimpleHelp
Affected product
SimpleHelp
Risk or reason
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Remedy or action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Official ID
CVE-2024-57726