SimpleHelp bug lets hackers create rogue remote support accounts
ID: eefea79f-72a2-543c-bdeb-a6fd9949db5a
STIX ID: report--eefea79f-72a2-543c-bdeb-a6fd9949db5a
Feed Name: Bleeping Computer
A critical OIDC validation vulnerability (CVE-2026-48558) in SimpleHelp allows unauthenticated attackers to create privileged Technician accounts that can remote into endpoints and execute scripts, bypassing MFA; SimpleHelp released fixes (5.5.16 and 6.0RC2) on June 9. The flaw affects servers using OIDC (generic or Azure AD) with a Technician Group configured for group-authenticated logins; researchers found ~14,000 public SimpleHelp servers with an estimated ~7.2% using OIDC, and recommended mitigations include patching or IP-based allowlists and monitoring new technician accounts and server logs for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
