• News/
  • bleepingcomputer-20260615200652

SimpleHelp bug lets hackers create rogue remote support accounts

BleepingComputer
·
Bill Toulas
·
Published Jun 15, 2026
·
Updated

A vulnerability in the SimpleHelp remote management software allows unauthenticated attackers to create privileged technician accounts on servers using the OpenID Connect (OIDC) authentication protocol. The flaw is tracked as CVE-2026-48558 and received a critical severity rating. It impacts SimpleHelp versions 5.5.15 and older, as well as 6.0 pre-release versions. Researchers at offensive security company Horizon3.ai explain that the issue is caused by how identity assertions received from an OIDC identity provider (IdP) are validated. When OIDC authentication is enabled, an unauthenticated attacker can create and log in as a new Technician user without needing to go through the multi-factor authentication (MFA) process. "This Technician, by default, can perform privileged management activities such as remoting into managed endpoints, executing scripts, and more," Horizon3.ai researcher Zach Hanley explains. SimpleHelp fixed the vulnerability on June 9 by releasing versions 5.5.16 and 6.0RC2 of the product. CVE-2026-48558 does not impact every SimpleHelp server running a vulnerable version; rather, it affects a subset that relies on the OIDC protocol, whether the generic one or Azure AD OIDC, both of them common in large enterprises. As the researchers explain, there are several prerequisites for the exploit to work: Results from Shodan show about 14,000 SimpleHelp servers exposed to the public internet. Analysis of a random sample suggests that roughly 7.2% are configured ...

Read full article

Affected Software

2 affected components
SimpleHelp remote management software<=5.5.15
SimpleHelp remote management software<6.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the SimpleHelp remote management software that allows hackers to create unauthorized technician accounts.

2

What security implications are discussed?

The vulnerability poses a significant risk as it allows unauthenticated attackers to gain privileged access to servers, potentially compromising sensitive data.

3

What products or software are affected?

The affected software is SimpleHelp remote management software.

4

What is the identifier for this vulnerability?

The vulnerability is tracked as CVE-2026-48558.

5

What is the severity rating of the vulnerability?

The flaw has received a critical severity rating.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203