OIDC Trust Flaw Lets SimpleHelp Create Admins

SimpleHelp’s OIDC login path turns into the control plane if its assertion check is wrong. On affected servers, an unauthenticated attacker can create a privileged Technician account, skip MFA, and then use the remote management console to reach enrolled endpoints. The bug is CVE-2026-48558. It affects SimpleHelp 5.5.15 and older, plus 6.0 pre-release builds, but only when OIDC authentication is enabled and a Technician Group is tied to the provider with group-authenticated logins allowed. SimpleHelp released 5.5.16 and 6.0RC2 on June 9. The risk is broader than one app account. A broken trust check in federated login can hand an outsider the same privileges the identity provider was supposed to protect, which matters most in tools that can push scripts or remote into managed systems.

Part of the PlainSec briefing for 2026-06-17

Sources