SimpleHelp has released patches for CVE-2026-48558, an authentication bypass vulnerability affecting deployments configured to use OpenID Connect (OIDC) authentication. The issue stems from how SimpleHelp validates identity provider assertions, allowing an unauthenticated attacker to create and authenticate as a new Technician account under certain configurations. Because Technician accounts can remotely access managed endpoints, execute scripts, and perform administrative actions, successful exploitation can lead to significant compromise of a managed environment. Horizon3.ai identified and responsibly disclosed the vulnerability to SimpleHelp.
The vulnerability affects SimpleHelp servers configured to use either generic OIDC or Azure AD OIDC authentication. An attacker can create and authenticate as a new Technician user when the following conditions exist:
Successful exploitation allows an attacker to:
According to Horizon3.ai’s research, approximately 14,000 SimpleHelp servers were exposed to the internet at the time of disclosure, with roughly 7.2% of sampled servers configured to use the vulnerable OIDC authentication method.
A NodeZero Rapid Response test has been developed to safely validate whether this authentication bypass can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.
Administrators should review all group-authenticated Technician accounts by navigating to:
Administration → Technicians → Gear Icon → Show Group Authenticated Users
Investigate any unfamiliar technician names or email addresses.
Review server logs for evidence of unauthorized technician registration, including entries similar to:
Registering technician login for [email protected] / (Technicians)
Configuration save requested (Forged Attacker - [email protected] [(Technicians)] [New Anon])
Relevant log locations:
| Indicator | Type | Description |
/opt/SimpleHelp/logs/server.log | Log File | Primary SimpleHelp server log |
/opt/SimpleHelp/logs/<YYYYMMDD-HHMMSS>/server.log | Log File | Historical server logs |
Registering technician login for ... | Log Entry | Evidence of technician creation |
Configuration save requested ... [New Anon] | Log Entry | Potential unauthorized technician registration |
Affected:
Patch:
Administration → Login Security
The NodeZero® platform empowers your organization to reduce your security risks by autonomously finding exploitable weaknesses in your network, giving you detailed guidance around how to priortize and fix them, and having you immediately verify that your fixes are effective.