PT-2026-48947 · Unknown · Simplehelp

CVE-2026-48558

·

Published

2026-06-12

·

Updated

2026-09-11

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SimpleHelp versions prior to 5.5.16 SimpleHelp versions prior to 6.0 RC2
Description An authentication bypass exists in the OpenID Connect (OIDC) authentication flow. The software fails to verify the cryptographic signature of identity tokens submitted during login. A remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session, which may also allow the bypass of multi-factor authentication (MFA). This issue allows attackers to remotely connect to managed endpoints, execute scripts with SYSTEM privileges, and perform administrative actions.
Approximately 1,000 internet-accessible instances are estimated to be vulnerable. Real-world exploitation has been observed where attackers used this flaw to deploy two malware families: TaskWeaver, a heavily obfuscated Node.js loader that establishes encrypted command-and-control channels, and Djinn Stealer, a cross-platform information stealer targeting cloud platform credentials, developer tools, source code management systems, and cryptocurrency wallets.
Recommendations Update SimpleHelp to version 5.5.16 or newer. Update SimpleHelp to version 6.0 RC2 or newer. As a temporary mitigation, restrict network access to the server. Review application logs for unfamiliar names and email addresses to identify potential unauthorized access.

Exploit

Fix

RCE

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48558

Affected Products

Simplehelp