
A security flaw in SimpleHelp remote management software enables unauthenticated attackers to generate privileged technician accounts on servers utilizing the OpenID Connect (OIDC) authentication protocol.
The vulnerability is identified as CVE-2026-48558 and has been assigned a critical severity rating. It affects SimpleHelp versions 5.5.15 and earlier, along with version 6.0 pre-release builds.
Researchers from offensive security firm Horizon3.ai note that the problem stems from the way identity assertions from an OIDC identity provider (IdP) are validated.
When OIDC authentication is active, an unauthenticated attacker can create and sign in as a new Technician user without having to undergo the multi-factor authentication (MFA) process.
"This Technician, by default, can perform privileged management activities such as remoting into managed endpoints, executing scripts, and more," explains Horizon3.ai researcher Zach Hanley.
SimpleHelp addressed the vulnerability on June 9 by releasing versions 5.5.16 and 6.0RC2 of the software.
Impact scope
CVE-2026-48558 does not affect every SimpleHelp server running a vulnerable version; instead, it impacts a subset that employs the OIDC protocol, whether the generic version or Azure AD OIDC, both of which are prevalent in large enterprises.
According to the researchers, several conditions must be met for the exploit to succeed:
OIDC authentication must be enabled
at least one Technician Group must be linked to the OIDC provider
the group must have “Allow group authenticated logins” turned on.
Shodan results show approximately 14,000 SimpleHelp servers exposed to the public internet.
Analysis of a random sample indicates that roughly 7.2% are set up to use OIDC authentication.
Furthermore, Horizon3.ai discovered that the “Allow group authenticated logins” setting is enabled in many instances.
Organizations can protect against attacks exploiting the CVE-2026-48558 vulnerability by updating to the latest SimpleHelp releases that fix the issue.
If updating is not feasible, a potential workaround is to limit technician login sources through IP-based allowlists.
The researchers have also provided indicators of compromise to help detect active exploitation, including new authenticated technician users with unknown or suspicious names and/or email addresses.
Additionally, logs in ‘/opt/SimpleHelp/logs/server.log’ and ‘/opt/SimpleHelp/logs/<YYYYMMDD-HHMMSS>/server.log’ may contain technician registrations, email addresses, and configuration changes made by rogue accounts.
Neither SimpleHelp nor Horizon3.ai has reported evidence of active exploitation.
However, given the product's history of drawing significant threat actor attention, organizations are advised to apply the available fixes or mitigations promptly.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
phpBB forum fixes auth bypass bug lurking for a decade
SAP fixes critical flaws in NetWeaver and Commerce Cloud
Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers bypass SonicWall VPN MFA due to incomplete patching