SimpleHelp fixes critical CVE-2026-48558 that lets attackers create rogue remote support accounts

A critical flaw in SimpleHelp remote management software can let an outsider create a privileged support account on vulnerable servers. The bug, CVE-2026-48558, affects SimpleHelp 5.5.15 and earlier plus 6.0 pre-release builds when OpenID Connect (OIDC) login is enabled and certain technician-group settings are in use. An unauthenticated attacker can bypass normal identity checks and multi-factor authentication to gain technician access; fixes are in 5.5.16 and 6.0RC2.
Why it matters: Organizations using SimpleHelp for remote administration could hand attackers the same kind of access trusted support staff have, including remote control of managed devices and script execution. This is urgent for anyone exposing SimpleHelp to the internet: update now, and if you cannot patch immediately, restrict technician logins with IP allowlists and review logs for suspicious new technician accounts.

Sources

CVE-2026-48558: Critical Authentication Bypass Vulnerability in SimpleHelp RMM Exploited for Credential Theft and Malware Delivery
Arctic Wolf Labs 2026.06.30 95% relevant
This source updates the same CVE-2026-48558 event with exploitation details: attackers are abusing the OIDC token-signature validation flaw to bypass MFA, gain technician-level access, steal credentials, and deploy custom malware. It also adds exposure estimates of about 14,000 internet-facing servers and roughly 1,000 directly vulnerable systems, plus CISA KEV urgency and mitigation guidance.
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
info@thehackernews.com (The Hacker News) 2026.06.30 95% relevant
This article advances the same underlying event by showing that CVE-2026-48558 is not just a disclosed flaw but is being actively exploited to create unauthorized access and deploy TaskWeaver and Djinn Stealer on victim systems.
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
Ionut Arghire 2026.06.30 96% relevant
This updates the same underlying CVE-2026-48558 SimpleHelp event by adding post-disclosure exploitation details: attackers used the auth-bypass flaw to obtain technician sessions and deploy TaskWeaver and Djinn Stealer, and CISA has now added the flaw to the KEV catalog.
SimpleHelp bug lets hackers create rogue remote support accounts
Bill Toulas 2026.06.15 100% relevant
This article establishes a new tracked story because it reports the disclosure and fix of CVE-2026-48558, a distinct SimpleHelp authentication flaw with no corresponding existing story in the tracker.
← Back to all stories