← All news

vulnerability

SimpleHelp Flaw Lets Attackers Create Rogue Technician Accounts

2026-06-16

A critical flaw in SimpleHelp's remote management software lets unauthenticated attackers create their own privileged technician accounts and waltz past multi-factor authentication on the way in. Tracked as CVE-2026-48558, it affects versions 5.5.15 and older, plus 6.0 pre-release builds. SimpleHelp shipped fixes on 9 June in 5.5.16 and 6.0RC2.

How the bug works

The weakness sits in how SimpleHelp validates identity assertions coming from an OpenID Connect provider. When OIDC is in play, the validation logic is loose enough that an outsider can register themselves as a technician and log straight in. No password, no MFA prompt, no awkward questions.

From that point, as Horizon3.ai researcher Zach Hanley points out, the account can do everything a real technician can: remote into managed endpoints, run scripts, poke around the environment. For a tool that exists specifically to give one person privileged access to many machines, that is roughly the worst possible failure mode.

Who is actually exposed

Not every SimpleHelp server is in the firing line. The bug only bites instances configured with OIDC, either the generic flavour or Azure AD OIDC, both common in larger enterprises that wanted single sign-on across their tooling.

Horizon3.ai ran a Shodan sweep and found roughly 14,000 SimpleHelp servers facing the public internet. Of a sampled subset, about 7.2% were running OIDC. A good number of those also had "Allow group authenticated logins" switched on, which broadens the attack surface further by letting any user matched to a group walk in.

No confirmed exploitation, yet

There is no confirmed in-the-wild abuse at the time of writing. That is the good news. The less good news is that SimpleHelp has been a favoured target in the past, including by ransomware crews who like remote-management tools precisely because they offer scale and stealth in one package. The gap between a public advisory and an opportunistic scan is usually measured in hours, not weeks.

What to do

  • Patch. Upgrade to 5.5.16 or 6.0RC2. This is the only clean fix.
  • If you can't patch immediately, restrict technician logins by IP allowlist. It is a blunt control, but it shuts the door for opportunistic scanners.
  • Check the logs. The server log at /opt/SimpleHelp/logs/server.log is worth a careful read for unfamiliar technician registrations or email addresses that nobody on the team recognises.

Remote-management software is one of those quiet pieces of infrastructure that nobody thinks about until it's the thing standing between an attacker and every endpoint you own. Worth a look this week.

SimpleHelp Flaw Lets Attackers Create Rogue Technician Accounts | RiskSense