Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    SimpleHelp bug lets hackers create rogue remote support accounts

    June 15, 2026

    DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act

    June 15, 2026

    The OPSEC Rave Wave (with Imani Thompson)

    June 15, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»SimpleHelp bug lets hackers create rogue remote support accounts
    News

    SimpleHelp bug lets hackers create rogue remote support accounts

    adminBy adminJune 15, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    SimpleHelp bug lets hackers create rogue remote support accounts

    A vulnerability in the SimpleHelp remote management software allows unauthenticated attackers to create privileged technician accounts on servers using the OpenID Connect (OIDC) authentication protocol.

    The flaw is tracked as CVE-2026-48558 and received a critical severity rating. It impacts SimpleHelp versions 5.5.15 and older, as well as 6.0 pre-release versions.

    Researchers at offensive security company Horizon3.ai explain that the issue is caused by how identity assertions received from an OIDC identity provider (IdP) are validated.

    image

    When OIDC authentication is enabled, an unauthenticated attacker can create and log in as a new Technician user without needing to go through the multi-factor authentication (MFA) process.

    “This Technician, by default, can perform privileged management activities such as remoting into managed endpoints, executing scripts, and more,” Horizon3.ai researcher Zach Hanley explains.

    SimpleHelp fixed the vulnerability on June 9 by releasing versions 5.5.16 and 6.0RC2 of the product.

    Impact scope

    CVE-2026-48558 does not impact every SimpleHelp server running a vulnerable version; rather, it affects a subset that relies on the OIDC protocol, whether the generic one or Azure AD OIDC, both of them common in large enterprises.

    As the researchers explain, there are several prerequisites for the exploit to work:

    • OIDC authentication must be enabled
    • at least one Technician Group must be associated with the OIDC provider
    • the group must have “Allow group authenticated logins” enabled.

    Results from Shodan show about 14,000 SimpleHelp servers exposed to the public internet.

    Analysis of a random sample suggests that roughly 7.2% are configured to use OIDC authentication.

    Additionally, Horizon3.ai found that the “Allow group authenticated logins” is enabled in many cases.

    Organizations can defend against attacks leveraging the CVE-2026-48558 vulnerability by updating to the latest SimpleHelp releases that address the issue.

    If updating is impossible, one mitigation is to restrict technician login sources using IP-based allowlists.

    Rogue Technician account on SimpleHelp
    Rogue Technician account on SimpleHelp
    Source: Horizon3.ai

    The researchers also shared indicators of compromise that can help detect active exploitation, such as new authenticated technician users with unknown or suspicious names and/or email addresses.

    Additionally, the logs in ‘/opt/SimpleHelp/logs/server.log’ and ‘/opt/SimpleHelp/logs//server.log’ may contain technician registrations, email addresses, and configuration changes performed by rogue accounts.

    Neither SimpleHelp nor Horizon3.ai has reported evidence of active exploitation.

    However, given the product’s history of attracting significant threat actor interest, organizations are advised to apply the available fixes or mitigations without delay.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
    admin
    • Website

    Related Posts

    News

    DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act

    June 15, 2026
    News

    The OPSEC Rave Wave (with Imani Thompson)

    June 15, 2026
    News

    It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests

    June 15, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202631 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202631 Views
    Our Picks

    SimpleHelp bug lets hackers create rogue remote support accounts

    June 15, 2026

    DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act

    June 15, 2026

    The OPSEC Rave Wave (with Imani Thompson)

    June 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.