PT-2026-48947 · Unknown · Simplehelp
CVE-2026-48558
·
Published
2026-06-12
·
Updated
2026-07-20
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SimpleHelp versions 5.5.1 through 5.5.15
SimpleHelp versions 6.0 pre-release through 6.0 RC1
Description
An authentication bypass exists in the OpenID Connect (OIDC) authentication flow. The server fails to verify the cryptographic signature of identity tokens submitted during login, allowing a remote, unauthenticated attacker to submit a forged token with arbitrary identity claims. This enables the attacker to obtain a fully authenticated technician session and, in some configurations, bypass multi-factor authentication. Approximately 1,000 instances are estimated to be vulnerable worldwide.
Real-world exploitation has been observed where attackers gained unauthorized access to technician sessions to deploy malware. This includes TaskWeaver, an obfuscated Node.js loader masquerading as a jQuery library, and Djinn Stealer, a cross-platform infostealer targeting Windows, macOS, and Linux. The malware harvests credentials from cloud platforms, developer tools, source code management systems, cryptocurrency wallets, and AI-assisted development tools. The attack is particularly critical for Managed Service Providers (MSPs) as a single compromised session can serve as a pivot point to all managed customer environments.
Recommendations
Update SimpleHelp versions 5.5.1 through 5.5.15 to version 5.5.16 or later.
Update SimpleHelp versions 6.0 pre-release through 6.0 RC1 to version 6.0 RC2 or later.
As a temporary mitigation, disable OIDC authentication or disable the Allow group authenticated logins parameter in Technician Group configurations.
Exploit
Fix
RCE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simplehelp