HIGHVulnerability
Verified
Global
CISA KEV: SimpleHelp SimpleHelp — SimpleHelp Missing Authorization Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Analysis
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. Added to CISA Known Exploited Vulnerabilities catalog on 2026-04-24. Remediation due: 2026-05-08.