TL;DR: A maximum-severity flaw in SimpleHelp’s remote-support software lets an attacker with no credentials forge a login token and walk in as a fully privileged “Technician” — and attackers are already doing exactly that, deploying two new malware families to raid cloud, developer and crypto-wallet credentials. CISA wants federal systems patched by tomorrow, 2 July 2026.

  • CVSS 10.0 (Critical) — the maximum possible score, unauthenticated, network-exploitable, no user interaction.
  • Lets an attacker forge an OIDC token and self-provision a privileged “Technician” account, bypassing MFA in the process.
  • Confirmed under active exploitation since late June 2026, deploying two new malware families: TaskWeaver and Djinn Stealer.
  • Added to CISA’s KEV catalogue on 29 June 2026 with a federal remediation deadline of 2 July 2026.
  • Fixed in SimpleHelp 5.5.16 (and 6.0 RC2/final) — patch immediately if OIDC authentication is enabled.
CRITICAL SimpleHelp OIDC Technician Bypass CVE-2026-48558
CVSS Score 10.0  (CVSS v3.1)
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type Authentication bypass via forged identity token  (CWE-347: Improper Verification of Cryptographic Signature)
Affected Products SimpleHelp server 5.5.x prior to 5.5.16 (with OIDC authentication configured), and 6.0 pre-release builds
Attack Vector Network — unauthenticated, no user interaction required
Actively Exploited Yes — in the wild since late June 2026  (CISA KEV added 29 June 2026; no public PoC released)
Patch Available Yes — fixed in SimpleHelp 5.5.16 (and 6.0 RC2 / final)
Disclosure Date 12 June 2026 (Horizon3.ai); CVE assigned 21 May 2026

Introduction

SimpleHelp is a remote monitoring and management (RMM) platform widely used by IT departments and managed service providers (MSPs) to remotely control endpoints, transfer files and run commands. That breadth of access is precisely why CVE-2026-48558 matters: it’s a maximum-severity authentication bypass in SimpleHelp’s OpenID Connect (OIDC) login flow that lets an unauthenticated attacker forge a valid identity token and register themselves as a fully privileged “Technician” — no password, no MFA, no user interaction. The flaw was found by Zach Hanley of Horizon3.ai using an internal, AI-assisted vulnerability-research pipeline, disclosed on 12 June 2026, and is now confirmed under active exploitation to deploy two previously unseen malware families, TaskWeaver and Djinn Stealer. CISA added it to the Known Exploited Vulnerabilities catalogue on 29 June 2026 with a remediation deadline of 2 July 2026.

How the SimpleHelp exploit works

SimpleHelp supports OIDC as a login method, commonly wired up to an identity provider such as Azure Active Directory, so organisations can offload technician authentication to their existing IdP. The bug sits in how the SimpleHelp server validates the identity assertions it receives back from the IdP during that OIDC flow — it fails to properly verify the cryptographic signature on the token, so it will accept a forged token containing attacker-chosen identity claims.

Because SimpleHelp will auto-provision a new “Technician” account for any OIDC identity it hasn’t seen before, an attacker who submits a forged token is granted a fresh, fully authenticated technician session on the spot. Technicians can remote into managed endpoints, execute scripts and transfer files by design — so this isn’t a low-privilege foothold, it’s the keys to every device the server manages.

It gets worse for organisations that believe MFA protects them here: SimpleHelp lets a technician self-register their own MFA method on first login. Since the attacker’s forged session is the first login for that fabricated identity, they simply enrol their own MFA factor and sail straight past the control meant to stop them.

Horizon3.ai has deliberately withheld the exact forgery technique to slow down copy-cat exploitation, but confirmed three preconditions for a server to be vulnerable:

  • OIDC authentication is enabled (generic OIDC or Azure AD OIDC).
  • A TechnicianGroup is linked to that OIDC provider.
  • “Allow group authenticated logins” is enabled on that TechnicianGroup — a setting Horizon3.ai says is commonly enabled in real deployments.
[ILLUSTRATIVE ONLY — not a working exploit]
Attacker submits a crafted OIDC callback request to the SimpleHelp
server's identity-provider callback endpoint, containing an ID token
whose claims (subject, email, group membership) are attacker-controlled.
The server accepts the token without validating its signature and
auto-provisions/authenticates a new Technician account bound to those
claims — granting the attacker a live, privileged technician session.

Is CVE-2026-48558 actively exploited?

Yes. BlackPoint Cyber’s Adversary Pursuit Group confirmed in-the-wild exploitation, reporting on 29 June 2026 that an unknown threat actor is abusing CVE-2026-48558 to obtain authenticated Technician sessions on internet-exposed SimpleHelp servers and pivot into every environment those servers manage. From that session, the attacker deploys TaskWeaver, a heavily obfuscated Node.js loader disguised as jquery.js and run through node.exe, which opens an encrypted command channel to attacker infrastructure (observed C2: a.dev-tunnels[.]com). TaskWeaver then fetches Djinn Stealer, a cross-platform (Windows/macOS/Linux) credential and secrets stealer that specifically targets cloud provider credentials (AWS, Azure, GCP, OCI and more), source-control and package-registry tokens, SSH keys, Docker/Helm auth, AI coding-assistant sessions (Claude, Gemini, Codex and others), and cryptocurrency wallets — before packaging everything into an AES-256-GCM-encrypted archive and exfiltrating it (observed exfil IP: 96.126.130[.]126:58942).

CISA added CVE-2026-48558 to its Known Exploited Vulnerabilities (KEV) catalogue on 29 June 2026, giving Federal Civilian Executive Branch agencies until 2 July 2026 to remediate. No public proof-of-concept exploit has been released; researchers have shared indicators of compromise instead of exploit code. Internet scans put roughly 14,000 SimpleHelp servers exposed to the internet, with an estimated 7.2% (~1,000 servers) configured with the vulnerable OIDC setup.

How to fix CVE-2026-48558: remediation & mitigation

Patch: Upgrade SimpleHelp server to 5.5.16 or later (or 6.0 RC2 / final if running a 6.0 pre-release). See SimpleHelp’s security advisory and updating guide for step-by-step instructions.

If you can’t patch immediately:

  • Disable OIDC authentication on any internet-facing server you cannot patch right away (Administration → Login Security). Note this breaks SSO/federated login for technicians until you patch.
  • Restrict technician login access to trusted IPs only via SimpleHelp’s Login Security settings, or place the server behind a firewall/VPN.
  • If you can’t disable OIDC, at minimum disable “Allow group authenticated logins” on any TechnicianGroup tied to an OIDC provider.

After patching:

  • Audit your technician roster (Administration → Technicians → Gear Icon → Show Group Authenticated Users) for unfamiliar names or email addresses, especially any created recently.
  • Review server logs (Administration → Server Logs, or on-disk at /opt/SimpleHelp/logs/server.log) for unexpected “Registering technician login for…” entries.
  • Terminate any suspicious technician sessions and rotate credentials for anything that server had access to.
  • Treat any confirmed compromise as a potential supply-chain incident — Djinn Stealer specifically targets downstream cloud, CI/CD and customer-environment credentials reachable from a compromised technician workstation.

Detection / IOCs:

  • Log string pattern: Registering technician login for <unfamiliar-name>@<domain> / (Technicians)
  • Log string pattern: Configuration save requested (Forged Attacker - ... [(Technicians)] [New Anon])
  • Malicious loader masquerading as jquery.js, executed via node.exe
  • C2 domain: a.dev-tunnels[.]com
  • Exfiltration endpoint: 96.126.130[.]126:58942

Frequently asked questions

Do I need OIDC enabled for my SimpleHelp server to be at risk?
Yes — the flaw only affects servers with OIDC authentication configured, a TechnicianGroup linked to that provider, and “Allow group authenticated logins” enabled. Servers using only local/password authentication are not exploitable via this specific bypass, but should still patch to 5.5.16.

Does enabling MFA protect me?
Not on its own. Because a forged session is treated as a brand-new technician’s first login, the attacker can self-register their own MFA method and bypass the protection entirely.

Is there a public exploit available?
No. Horizon3.ai has withheld the exact forgery technique, and no public proof-of-concept has surfaced as of this writing. That hasn’t stopped active exploitation — attackers appear to have independently developed a working technique.

What should MSPs specifically do?
Treat this as a supply-chain risk. A single compromised SimpleHelp server can expose every downstream customer environment it manages. Patch immediately, then audit technician accounts and logs across every managed instance, not just your own infrastructure.

Sources & further reading

ZeroDayHub tracks critical vulnerabilities as they break. Subscribe for updates.

Leave a Reply

Trending

Discover more from Zerodayhub

Subscribe now to keep reading and get access to the full archive.

Continue reading