Vulnerabilities · 90 days ago

OIDC Trust Flaw Lets SimpleHelp Create Admins

SimpleHelp’s OIDC login path turns into the control plane if its assertion check is wrong. On affected servers, an unauthenticated attacker can create a privileged Technician account, skip MFA, and then use the remote management console to reach enrolled endpoints.

The bug is CVE-2026-48558. It affects SimpleHelp 5.5.15 and older, plus 6.0 pre-release builds, but only when OIDC authentication is enabled and a Technician Group is tied to the provider with group-authenticated logins allowed. SimpleHelp released 5.5.16 and 6.0RC2 on June 9.

The risk is broader than one app account. A broken trust check in federated login can hand an outsider the same privileges the identity provider was supposed to protect, which matters most in tools that can push scripts or remote into managed systems.

CVE-2026-48558

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: simpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. EPSS 64% (99th percentile).

CISA federal remediation date Jul 2

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-06-17

Editions

Related stories