CVE-2026-48558 – Critical Authentication Bypass in SimpleHelp RMM OIDC Flow
Key Takeaways
- Severity: Critical (CVSS 10.0 / 9.5)
- Impact: Unauthenticated attackers can bypass OIDC authentication, obtain a fully‑privileged Technician session, and deploy malware such as Djinn Stealer.
- Affected: SimpleHelp ≤ 5.5.15 and 6.0 pre‑release.
- Threat status: Active exploitation observed; listed in CISA KEV.
- Action: Apply the vendor patch now and monitor for rogue technician activity.
Overview
The CVE-2026-48558 vulnerability is a Critical authentication bypass in the OpenID Connect (OIDC) flow of SimpleHelp remote monitoring and management (RMM) software. When OIDC authentication is enabled, the server accepts identity tokens without verifying their cryptographic signature. An unauthenticated attacker can craft a token with arbitrary claims, obtain a fully‑authenticated Technician session, and in many deployments bypass multi‑factor authentication (MFA). This grants remote control over managed endpoints, script execution, and the ability to install additional payloads.
Technical Details
- Root cause: The OIDC token verification routine skips signature validation, violating CWE‑347 (Improper Verification of Cryptographic Signature).
- Attack flow:
- Attacker creates a forged JWT containing a
role=Technicianclaim. - Submits the token to the SimpleHelp login endpoint.
- Server accepts the token and creates a Technician session cookie.
- Attacker uses the session to execute remote commands, retrieve data, and push additional modules.
- Attacker creates a forged JWT containing a
- Malware delivery: Real‑world campaigns have leveraged this bypass to drop the Djinn Stealer and TaskWeaver loaders. Djinn Stealer harvests cloud credentials, source code, AI‑tool tokens, browsers, SSH keys, and cryptocurrency wallets.
- Exploitation timeline: Active exploitation was first reported on 2026‑06‑14. The most intense day was 2026‑06‑30, with 44 exploitation events, 5 distinct exploit tools, and 15 references to patches. A spike in mentions followed the addition to the CISA KEV catalog on 2026‑06‑29.
- Detection evidence: Logs show unexpected Technician session creation from unknown IPs, OIDC token payloads lacking a
kidfield, and outbound connections to known Djinn Stealer C2 domains.
Severity & Impact
| Metric | Value |
|---|---|
| CVE | CVE-2026-48558 |
| Vendor | simple-help |
| Product | SimpleHelp |
| CVSS v3.1 | 10.0 (Critical) |
| CVSS v4.0 | 9.5 (Critical) |
| CWE | CWE‑347 |
| Exploited? | Active exploitation |
| CISA KEV | Yes |
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) reflects a remote‑only attack with no user interaction, granting full confidentiality, integrity, and availability compromise across all managed endpoints.
Affected Products
- Vendor: simple-help
- Product: SimpleHelp RMM
- Versions: 5.5.15 and earlier; 6.0 pre‑release (OIDC enabled)
For the complete list of affected versions, see the VulnSocial CVE page.
Actionable Insights – What to Monitor
- Authentication logs: Look for Technician session creation from IPs that have never logged in before.
- OIDC token anomalies: Tokens without a
kidor with unsigned payloads (alg:none). - Endpoint behavior: Unexpected PowerShell/Command‑Prompt execution, new scheduled tasks, or remote script launches from the RMM console.
- Network traffic: Outbound connections to known Djinn Stealer C2 IP ranges (see IOCs in the vendor advisory).
- Patch adoption: Track which hosts have applied the SimpleHelp security update; correlate with the VulnSocial activity timeline.
Remediation & Mitigation
- Apply the vendor patch – upgrade SimpleHelp to a version that validates OIDC token signatures.
https://simple-help.com/security/simplehelp-security-update-2026-05 - If immediate patching is not possible, disable OIDC authentication in the RMM configuration or enforce strict token validation via a reverse‑proxy.
- Enforce MFA for all Technician accounts and audit existing MFA configurations for bypass attempts.
- Restrict network access – limit RMM server exposure to trusted management subnets and block inbound traffic from the internet.
- Implement detection rules:
- Alert on creation of Technician sessions without prior MFA.
- Flag JWTs with
alg:noneor missing signatures. - Monitor for file hashes associated with Djinn Stealer (see vendor IOCs).
- Conduct forensic triage per CISA’s “Forensics Triage Requirements” and BOD 26‑04 guidance to verify if the breach has been leveraged.
Bottom Line
CVE-2026-48558 is a Critical authentication bypass that is actively exploited in the wild to deliver credential‑stealing malware. Organizations running SimpleHelp RMM must patch immediately, disable vulnerable OIDC configurations, and monitor for rogue technician sessions to mitigate the severe risk.
References
- https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
- https://simple-help.com/release-news
- https://simple-help.com/security/simplehelp-security-update-2026-05
- https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48558
