CVE-2024-57726
Description
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Summary dbcve.org
SimpleHelp v5.5.7 and prior contains a privilege escalation vulnerability where low-privilege technicians can create API keys with excessive permissions beyond their assigned role. These over-privileged API keys can then be used to perform actions reserved for server administrators, effectively allowing lateral movement to full administrative control of the SimpleHelp server.
Mitigation
Apply vendor-provided patch for SimpleHelp v5.5.7 or later; immediately audit existing API keys for excessive permissions and revoke any unauthorized admin-level keys; consider restricting API key creation permissions until patch is applied.