A new critical vulnerability in SimpleHelp has caused significant concern in the cybersecurity community, as it allows unauthorized users to gain access to elevated technician accounts without having to bypass multi-factor authentication mechanisms.

The vulnerability, listed as CVE-2026-48558, affects SimpleHelp versions 5.5.15 and earlier, as well as 6.0 pre-release versions. While there is no information available to confirm active exploitation by cybercriminals, experts warn that organizations should not wait until the first incidents appear.
How the vulnerability works in SimpleHelp
According to the analysis by the company Horizon3.ai, the problem lies in the way SimpleHelp processes and verifies the identity information it receives through the OpenID Connect, also known as OIDC.
See also: SimpleHelp and ScreenConnect misused for phishing attacks
OpenID Connect is one of the most popular unified sign-in methods in enterprise environments. It allows users to authenticate through external identity providers, reducing the need to manage multiple passwords.
However, in the case of SimpleHelp, the validation process for certain identity details proved to be incomplete. This allows an attacker to create a new technician account and gain access to the system without successfully completing the multi-factor authentication process.
What can attackers do?
The most worrying aspect of the case is that technician accounts on SimpleHelp have extensive administrative rights by default.
This means that an attacker who exploits the vulnerability can remotely connect to managed systems, execute scripts, gain access to critical data, modify security settings , and affect an organization's entire infrastructure.
In environments where SimpleHelp is used by IT service providers or technical support teams, this access could be a starting point for broader attacks across multiple corporate networks.
Which facilities are affected?
Although the vulnerability is rated critical, not all servers running vulnerable versions of the software are exposed.
In order for the issue to be exploited, certain conditions must be met. First, enabled authentication OIDC must be . Second, at least one technician group must be connected to the identity provider . Third, the option that allows group-based authentication must be enabled .
See also: Crazy ransomware: Abuse of legitimate employee monitoring tool
These requirements theoretically limit the number of vulnerable installations, however the actual extent of the problem remains significant.

Thousands of servers exposed to the internet
Data collected by researchers through the Shodan reveals that approximately 14,000 SimpleHelp servers are accessible via the public internet.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Analysis of a random sample showed that approximately 7.2% of these use OIDC authentication, which translates to hundreds of potentially vulnerable installations worldwide.
At the same time, Horizon3.ai found that the group authentication option is enabled in a large number of installations, increasing the potential risk.
The fixes are already available
The developer of SimpleHelp reacted relatively quickly after the discovery of the problem, releasing security updates that fix the vulnerability.
The safe versions are SimpleHelp 5.5.16 and 6.0RC2, with experts recommending the immediate upgrade of all affected systems.
In cases where the installation of updates cannot be carried out immediately, it is recommended to implement temporary protection measures, such as the use of IP-based allowlists to restrict access to technical users.
How administrators can detect a potential violation
Organizations are also urged to carefully review system logs for signs of suspicious activity
New technician accounts with unfamiliar names or unusual email addresses can be a sign of a breach. Additionally, administrators should look for unexpected changes to system settings or new user registrations created without authorization.
See also: Abuse of RMM tools to distribute Medusa & DragonForce ransomware
Particular attention is recommended to the log files located in the paths /opt/SimpleHelp/logs/server.log and /opt/SimpleHelp/logs//server.log, where suspicious account actions may be recorded.

Another bell for remote management tools
This case highlights once again the critical role that remote management tools play in modern cybersecurity. Solutions like SimpleHelp are valuable tools for businesses, but at the same time they are particularly attractive targets for cybercriminals, as they offer access to a large number of systems through a single point of control.
Even though no active exploitation of the CVE-2026-48558 vulnerability has been recorded so far, history has shown that attackers closely monitor the publication of new security vulnerabilities. For this reason, organizations using SimpleHelp should proceed with the necessary updates and checks immediately, before the theoretical threat turns into a real security incident.
Source: www.bleepingcomputer.com
