PT-2026-48947 · Unknown · Simplehelp
CVE-2026-48558
·
Published
2026-06-12
·
Updated
2026-09-11
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SimpleHelp versions prior to 5.5.16
SimpleHelp versions prior to 6.0 RC2
Description
An authentication bypass exists in the OpenID Connect (OIDC) authentication flow. The software fails to verify the cryptographic signature of identity tokens submitted during login. A remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session, which may also allow the bypass of multi-factor authentication (MFA). This issue allows attackers to remotely connect to managed endpoints, execute scripts with SYSTEM privileges, and perform administrative actions.
Approximately 1,000 internet-accessible instances are estimated to be vulnerable. Real-world exploitation has been observed where attackers used this flaw to deploy two malware families: TaskWeaver, a heavily obfuscated Node.js loader that establishes encrypted command-and-control channels, and Djinn Stealer, a cross-platform information stealer targeting cloud platform credentials, developer tools, source code management systems, and cryptocurrency wallets.
Recommendations
Update SimpleHelp to version 5.5.16 or newer.
Update SimpleHelp to version 6.0 RC2 or newer.
As a temporary mitigation, restrict network access to the server.
Review application logs for unfamiliar names and email addresses to identify potential unauthorized access.
Exploit
Fix
RCE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simplehelp