Nearly 14,000 SimpleHelp Servers Exposed After Critical Authentication Bypass Disclosure
Nearly 14,000 internet-facing SimpleHelp servers are exposed after the disclosure of a critical authentication bypass vulnerability tracked as CVE-2026-48558. The flaw affects SimpleHelp deployments that use OpenID Connect authentication, including generic OIDC and Azure AD or Microsoft Entra ID setups, according to the Horizon3.ai disclosure.
The issue can let a remote, unauthenticated attacker create and access a new Technician session on a vulnerable server. In SimpleHelp, technician access can allow remote control of managed endpoints, script execution, monitoring, and other administrative actions, making the bug especially dangerous for managed service providers and enterprise IT teams.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The Tenable CVE page says SimpleHelp versions 5.5.15 and earlier, along with 6.0 pre-release versions, are affected. SimpleHelp has released fixed builds through its SimpleHelp security notice, including SimpleHelp 5.5.16 for 5.5.x users and SimpleHelp 6.0 RC2 for 6.0 users.
What CVE-2026-48558 Allows Attackers to Do
CVE-2026-48558 exists in the OIDC authentication flow. The core problem is that identity tokens submitted during login can be accepted without proper cryptographic signature verification, allowing an attacker to submit forged identity claims and obtain a technician session.
That matters because SimpleHelp is a remote monitoring and management platform. A rogue technician account may give an attacker a direct path into systems that the SimpleHelp server manages, depending on how the environment is configured and what permissions the technician group receives.

Multi-factor authentication may not stop the attack in some affected setups. Horizon3.ai said the flaw can allow an attacker to bypass MFA because a new technician can register their own authentication method during first login.
Which SimpleHelp Servers Are at Risk
Not every SimpleHelp server is exploitable. The vulnerable path requires OIDC authentication to be configured, a TechnicianGroup to be linked to the OIDC provider, and the option to allow group-authenticated logins to be enabled.
These settings often appear in enterprise deployments because OIDC lets companies centralize login through an identity provider. SimpleHelp added OpenID Connect support for technicians in version 5.5.0, according to the companyโs SimpleHelp release notes.
| Item | Details |
|---|---|
| CVE | CVE-2026-48558 |
| Severity | Critical, with a CVSS v3 score of 10.0 listed by Tenable |
| Affected versions | SimpleHelp 5.5.15 and earlier, plus SimpleHelp 6.0 pre-release versions |
| Fixed versions | SimpleHelp 5.5.16 and SimpleHelp 6.0 RC2 |
| Required condition | OIDC authentication configured in a vulnerable way |
Exposure Grew from 3,400 to Nearly 14,000 Servers
The exposure numbers make the issue urgent. Horizon3.ai said the number of publicly reachable SimpleHelp servers rose from about 3,400 in early 2025 to nearly 14,000 in June 2026. Its random sampling found that about 7.2% of those systems used the vulnerable OIDC authentication method.
That does not mean every exposed server can be taken over. It does show a broad attack surface for a remote access product, and attackers often focus on RMM tools because they already have trusted access to downstream machines.
BleepingComputer reported that neither SimpleHelp nor Horizon3.ai had reported evidence of active exploitation at the time of its coverage. Even so, the publication noted SimpleHelp’s recent history of attracting threat actor interest, which raises the urgency for patching.
How Administrators Can Check for Compromise
Security teams should review technician accounts inside SimpleHelp and look for unfamiliar names, email addresses, or recently created accounts. Admins should check group-authenticated users in the Technicians section and review server logs for suspicious technician registration events.

Admins should also inspect server-side logs, including files under /opt/SimpleHelp/logs/server.log and archived log folders. Look for unexpected technician registrations, configuration changes, or logins tied to unknown email addresses.
- Review all technician accounts, including group-authenticated users.
- Search server logs for unfamiliar email addresses and technician names.
- Check for unexpected configuration changes made by new or unknown users.
- Confirm which technician groups can use OIDC authentication.
- Document any suspicious activity before changing or deleting accounts.
What SimpleHelp Customers Should Do Now
SimpleHelp customers should update affected servers as soon as possible. The companyโs security update says action is required for 5.5.x and 6.0 pre-release deployments and provides downloads for the fixed releases.
The companyโs release news also identifies SimpleHelp 5.5.16 as a security-focused release that closes a critical vulnerability and recommends the update for all users. Customers who cannot patch immediately should restrict technician login access by IP address through Login Security and review their OIDC configuration.
Organizations should treat this as a high-priority identity and remote access incident, not just a routine software update. RMM products sit close to endpoints, servers, and help desk workflows, so a compromised technician account can create outsized damage.
The practical message is simple: patch first, then audit. BleepingComputer also highlighted that the flaw does not affect every server, but it can give attackers privileged remote support access when the required OIDC settings exist.
| Date | Event |
|---|---|
| May 21, 2026 | Horizon3.ai discovered and validated the authentication bypass. |
| May 22, 2026 | The issue was reported to SimpleHelp. |
| June 9, 2026 | Horizon3.ai observed that SimpleHelp had released patches. |
| June 12, 2026 | Horizon3.ai published indicators of compromise and mitigation guidance. |
| June 15, 2026 | Public vulnerability databases and security coverage continued to track the issue. |
FAQ
CVE-2026-48558 is a critical SimpleHelp authentication bypass vulnerability in the OIDC login flow. It can let a remote, unauthenticated attacker create a technician session on a vulnerable server.
The affected versions are SimpleHelp 5.5.15 and earlier, plus SimpleHelp 6.0 pre-release versions. SimpleHelp 5.5.16 and SimpleHelp 6.0 RC2 address the issue.
No. The attack path depends on OIDC authentication being configured, a TechnicianGroup being connected to the OIDC provider, and group-authenticated logins being allowed.
MFA may not stop the attack in some vulnerable configurations because the attacker can create a new technician session and register their own MFA method during the first login.
Administrators should update to the fixed SimpleHelp releases, review technician accounts, inspect server logs for suspicious registrations or configuration changes, and restrict technician login access by IP address if immediate patching is not possible.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages