Nearly 14,000 SimpleHelp Servers Exposed After Critical Authentication Bypass Disclosure


Nearly 14,000 internet-facing SimpleHelp servers are exposed after the disclosure of a critical authentication bypass vulnerability tracked as CVE-2026-48558. The flaw affects SimpleHelp deployments that use OpenID Connect authentication, including generic OIDC and Azure AD or Microsoft Entra ID setups, according to the Horizon3.ai disclosure.

The issue can let a remote, unauthenticated attacker create and access a new Technician session on a vulnerable server. In SimpleHelp, technician access can allow remote control of managed endpoints, script execution, monitoring, and other administrative actions, making the bug especially dangerous for managed service providers and enterprise IT teams.

The Tenable CVE page says SimpleHelp versions 5.5.15 and earlier, along with 6.0 pre-release versions, are affected. SimpleHelp has released fixed builds through its SimpleHelp security notice, including SimpleHelp 5.5.16 for 5.5.x users and SimpleHelp 6.0 RC2 for 6.0 users.

What CVE-2026-48558 Allows Attackers to Do

CVE-2026-48558 exists in the OIDC authentication flow. The core problem is that identity tokens submitted during login can be accepted without proper cryptographic signature verification, allowing an attacker to submit forged identity claims and obtain a technician session.

That matters because SimpleHelp is a remote monitoring and management platform. A rogue technician account may give an attacker a direct path into systems that the SimpleHelp server manages, depending on how the environment is configured and what permissions the technician group receives.

Indicators of Compromise

Multi-factor authentication may not stop the attack in some affected setups. Horizon3.ai said the flaw can allow an attacker to bypass MFA because a new technician can register their own authentication method during first login.

Which SimpleHelp Servers Are at Risk

Not every SimpleHelp server is exploitable. The vulnerable path requires OIDC authentication to be configured, a TechnicianGroup to be linked to the OIDC provider, and the option to allow group-authenticated logins to be enabled.

These settings often appear in enterprise deployments because OIDC lets companies centralize login through an identity provider. SimpleHelp added OpenID Connect support for technicians in version 5.5.0, according to the companyโ€™s SimpleHelp release notes.

ItemDetails
CVECVE-2026-48558
SeverityCritical, with a CVSS v3 score of 10.0 listed by Tenable
Affected versionsSimpleHelp 5.5.15 and earlier, plus SimpleHelp 6.0 pre-release versions
Fixed versionsSimpleHelp 5.5.16 and SimpleHelp 6.0 RC2
Required conditionOIDC authentication configured in a vulnerable way

Exposure Grew from 3,400 to Nearly 14,000 Servers

The exposure numbers make the issue urgent. Horizon3.ai said the number of publicly reachable SimpleHelp servers rose from about 3,400 in early 2025 to nearly 14,000 in June 2026. Its random sampling found that about 7.2% of those systems used the vulnerable OIDC authentication method.

That does not mean every exposed server can be taken over. It does show a broad attack surface for a remote access product, and attackers often focus on RMM tools because they already have trusted access to downstream machines.

BleepingComputer reported that neither SimpleHelp nor Horizon3.ai had reported evidence of active exploitation at the time of its coverage. Even so, the publication noted SimpleHelp’s recent history of attracting threat actor interest, which raises the urgency for patching.

How Administrators Can Check for Compromise

Security teams should review technician accounts inside SimpleHelp and look for unfamiliar names, email addresses, or recently created accounts. Admins should check group-authenticated users in the Technicians section and review server logs for suspicious technician registration events.

SimpleHelp offers optional settings to enhance Technician login security

Admins should also inspect server-side logs, including files under /opt/SimpleHelp/logs/server.log and archived log folders. Look for unexpected technician registrations, configuration changes, or logins tied to unknown email addresses.

  • Review all technician accounts, including group-authenticated users.
  • Search server logs for unfamiliar email addresses and technician names.
  • Check for unexpected configuration changes made by new or unknown users.
  • Confirm which technician groups can use OIDC authentication.
  • Document any suspicious activity before changing or deleting accounts.

What SimpleHelp Customers Should Do Now

SimpleHelp customers should update affected servers as soon as possible. The companyโ€™s security update says action is required for 5.5.x and 6.0 pre-release deployments and provides downloads for the fixed releases.

The companyโ€™s release news also identifies SimpleHelp 5.5.16 as a security-focused release that closes a critical vulnerability and recommends the update for all users. Customers who cannot patch immediately should restrict technician login access by IP address through Login Security and review their OIDC configuration.

Organizations should treat this as a high-priority identity and remote access incident, not just a routine software update. RMM products sit close to endpoints, servers, and help desk workflows, so a compromised technician account can create outsized damage.

The practical message is simple: patch first, then audit. BleepingComputer also highlighted that the flaw does not affect every server, but it can give attackers privileged remote support access when the required OIDC settings exist.

DateEvent
May 21, 2026Horizon3.ai discovered and validated the authentication bypass.
May 22, 2026The issue was reported to SimpleHelp.
June 9, 2026Horizon3.ai observed that SimpleHelp had released patches.
June 12, 2026Horizon3.ai published indicators of compromise and mitigation guidance.
June 15, 2026Public vulnerability databases and security coverage continued to track the issue.

FAQ

What is CVE-2026-48558?

CVE-2026-48558 is a critical SimpleHelp authentication bypass vulnerability in the OIDC login flow. It can let a remote, unauthenticated attacker create a technician session on a vulnerable server.

Which SimpleHelp versions are affected by CVE-2026-48558?

The affected versions are SimpleHelp 5.5.15 and earlier, plus SimpleHelp 6.0 pre-release versions. SimpleHelp 5.5.16 and SimpleHelp 6.0 RC2 address the issue.

Are all SimpleHelp servers vulnerable?

No. The attack path depends on OIDC authentication being configured, a TechnicianGroup being connected to the OIDC provider, and group-authenticated logins being allowed.

Can MFA stop this SimpleHelp attack?

MFA may not stop the attack in some vulnerable configurations because the attacker can create a new technician session and register their own MFA method during the first login.

What should SimpleHelp administrators do now?

Administrators should update to the fixed SimpleHelp releases, review technician accounts, inspect server logs for suspicious registrations or configuration changes, and restrict technician login access by IP address if immediate patching is not possible.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages