SimpleHelp OIDC Flaw Enables Auth Bypass
A SimpleHelp authentication bypass flaw lets unauthenticated attackers forge OIDC tokens to create Technician accounts and take over managed endpoints.
CVE-2026-48558 is an authentication bypass vulnerability in SimpleHelp, a self-hosted remote support and access tool widely used by IT teams and MSPs. The flaw affects deployments configured with OpenID Connect (OIDC) authentication, allowing remote, unauthenticated attackers to submit forged tokens containing arbitrary claims. This enables creation of new 'Technician' accounts, bypassing multi-factor authentication and granting full access to managed endpoints.
Exploitation requires specific but commonly encountered conditions: OIDC must be enabled, a TechnicianGroup must be associated with the OIDC provider, and the 'Allow group authenticated logins' setting must be active on that group—a configuration MS-ISAC notes is typically present in real-world deployments. Successful abuse would let attackers remotely control managed endpoints, execute scripts, install software, and view, modify, or delete data.
Given SimpleHelp's use by MSPs managing multiple downstream clients, exploitation could enable lateral compromise across customer environments, similar to prior supply-chain-style abuse of remote management tools. No in-the-wild exploitation has been reported at this time. Affected versions are SimpleHelp prior to v5.5.16 (stable) and pre-release v6.0 RC 2; organizations should patch promptly and review OIDC/TechnicianGroup configurations.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-simplehelp-could-allow-for-authentication-bypass_2026-061
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free