CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Other sources
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57726?
CVE-2024-57726 is a high-severity vulnerability that allows unauthorized API key creation, enabling privilege escalation.
How do I fix CVE-2024-57726?
To fix CVE-2024-57726, upgrade SimpleHelp to version 5.5.8 or later to eliminate the excessive permissions for API keys.
Who is affected by CVE-2024-57726?
CVE-2024-57726 affects all versions of SimpleHelp remote support software up to and including v5.5.7.
What can attackers do with the CVE-2024-57726 vulnerability?
Attackers can exploit CVE-2024-57726 to create API keys that grant them unauthorized access and potentially elevate their privileges to server admin.
What is SimpleHelp and its relation to CVE-2024-57726?
SimpleHelp is remote support software, and CVE-2024-57726 identifies a security flaw in it that allows for privilege escalation through API keys.