Researchers disclosed CVE-2026-48558, a maximum-severity authentication bypass in SimpleHelp remote management software that allows unauthenticated attackers to forge OpenID Connect identity tokens and log in as a technician. The flaw affects SimpleHelp 5.5.15 and earlier, along with 6.0 pre-release versions, because the OIDC login flow accepts submitted JWT identity tokens without verifying their cryptographic signature. The issue is rated CVSS 10.0 and mapped to CWE-347, with no user interaction required for exploitation.
Successful exploitation can give attackers an authenticated technician session with administrative reach into managed environments, including remote access to endpoints, script execution, and in some cases MFA bypass because technician accounts can enroll their own MFA method at first login. Horizon3.ai said the bug affects deployments using generic OIDC and Azure Active Directory OIDC, and estimated that internet-exposed SimpleHelp servers have grown to nearly 14,000, with about 7.2% using the vulnerable configuration. Defenders were urged to apply vendor patches immediately, restrict technician authentication by IP where patching is delayed, and review technician accounts and server logs for signs of compromise.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
After adding CVE-2026-48558 to the Known Exploited Vulnerabilities catalog, CISA directed U.S. federal civilian agencies to remediate the SimpleHelp flaw by 2026-07-02. The order followed evidence of active exploitation in the wild.
CISA added CVE-2026-48558, the SimpleHelp OIDC authentication bypass flaw, to its Known Exploited Vulnerabilities catalog, reflecting active exploitation concern. The listing elevated urgency for organizations using SimpleHelp, particularly MSPs, to remediate and review exposure.
By 2026-06-29, attackers were reported actively exploiting CVE-2026-48558 on internet-facing SimpleHelp servers to create privileged access and use the platform as a trusted channel into managed systems. Blackpoint linked the intrusions to delivery of the newly identified TaskWeaver malware and Djinn Stealer, which targets credentials, cloud secrets, developer tooling, and cryptocurrency wallets across Windows, macOS, and Linux.
Researchers disclosed CVE-2026-48558, a maximum-severity authentication bypass in SimpleHelp affecting versions 5.5.15 and earlier and 6.0 pre-release versions. The flaw allows unauthenticated attackers to forge OIDC identity tokens without signature verification and obtain an authenticated technician session, with possible MFA bypass in some cases.
SimpleHelp released fixes for CVE-2026-48558 on 2026-06-09 in versions 5.5.16 and 6.0RC2. The patch addressed an OIDC authentication flaw that could let unauthenticated attackers create privileged Technician accounts and potentially bypass MFA.
According to the Canadian Centre for Cyber Security advisory, SimpleHelp published a security update on 2026-05-26 for vulnerabilities affecting versions 5.5.0 through before 5.5.16 and 6.0 through before 6.0 RC2. The notice directs users and administrators to review the vendor advisories and apply the update.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcecyber.gc.ca
Open sourcethecyberthrone.in
Open sourcesecurityonline.info
Open sourcehorizon3.ai
Open sourcecve.org
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.