PT-2026-48947 · Unknown · Simplehelp

CVE-2026-48558

·

Published

2026-06-12

·

Updated

2026-07-20

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SimpleHelp versions 5.5.1 through 5.5.15 SimpleHelp versions 6.0 pre-release through 6.0 RC1
Description An authentication bypass exists in the OpenID Connect (OIDC) authentication flow. The server fails to verify the cryptographic signature of identity tokens submitted during login, allowing a remote, unauthenticated attacker to submit a forged token with arbitrary identity claims. This enables the attacker to obtain a fully authenticated technician session and, in some configurations, bypass multi-factor authentication. Approximately 1,000 instances are estimated to be vulnerable worldwide.
Real-world exploitation has been observed where attackers gained unauthorized access to technician sessions to deploy malware. This includes TaskWeaver, an obfuscated Node.js loader masquerading as a jQuery library, and Djinn Stealer, a cross-platform infostealer targeting Windows, macOS, and Linux. The malware harvests credentials from cloud platforms, developer tools, source code management systems, cryptocurrency wallets, and AI-assisted development tools. The attack is particularly critical for Managed Service Providers (MSPs) as a single compromised session can serve as a pivot point to all managed customer environments.
Recommendations Update SimpleHelp versions 5.5.1 through 5.5.15 to version 5.5.16 or later. Update SimpleHelp versions 6.0 pre-release through 6.0 RC1 to version 6.0 RC2 or later. As a temporary mitigation, disable OIDC authentication or disable the Allow group authenticated logins parameter in Technician Group configurations.

Exploit

Fix

RCE

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48558

Affected Products

Simplehelp