Publication of an exploit (PoC) for SimpleHelp (CVE-2026-48558)

Dark Web2026-07-01, 12:40
For informational purposes only
Type of vulnerability: Authentication Bypass Affected versions: SimpleHelp 5.5.15 and lower, 6.0 RC1 and lower (with OIDC authentication enabled) Privileges obtained: SYSTEM
The author attaches a Python exploit for CVE-2026-48558 — a critical vulnerability in SimpleHelp, disclosed by Horizon3.ai on June 12, 2026, with a base CVSS score of 10. The vulnerability lies in incorrect validation of identity provider assertions in SimpleHelp's OIDC authentication: an unauthenticated attacker with access to the server's OIDC callback endpoint can create their own Technician account and log in on their behalf, bypassing MFA (because the technician configures it themselves on the first login). With this level of access, they can remotely connect to managed endpoints, run scripts as SYSTEM, and perform other administrative actions.
SimpleHelp is a commercial RMM (Remote Monitoring & Management) platform used by internal IT teams and MSP providers for remote support of end users. According to Horizon3.ai, at the time of disclosure, approximately 14,000 SimpleHelp servers were accessible on the internet, of which about 7.2% used OIDC authentication — meaning the potentially vulnerable subset is around 1,000 instances. In most of the environments checked by Horizon3.ai, the "Allow group authenticated logins" parameter, necessary for exploitation, was enabled. It's worth noting that the vulnerability was detected by an autonomous AI system Horizon3.ai called Sua Sponte.
SimpleHelp has already been involved in the context of ransomware groups: initial vulnerabilities in January 2025 formed the basis for a series of attacks by DragonForce and other operators, one of which was added to the CISA KEV catalog in May 2025, and two more in April 2026.
Vulnerabilities
10
CVE-2026-48558
Vendors
Simplehelp
Horizon3.Ai
Products
Simplehelp
Sua Sponte