VULNERABILITY OVERVIEW
SimpleHelp fails to verify the cryptographic signature of OIDC identity tokens when generic OIDC or Azure AD OIDC authentication is configured with group-authenticated logins enabled. An unauthenticated attacker can forge a token to obtain a fully authenticated 'Technician' session — bypassing MFA on first login — and then remotely access all managed endpoints, execute scripts, and pivot across the entire MSP customer base. Confirmed in-the-wild exploitation by an unknown threat actor has delivered two novel malware families: TaskWeaver (an obfuscated Node.js loader) and Djinn Stealer (a cross-platform credential/cloud-token harvester targeting Windows, macOS, and Linux). CISA added to KEV on June 29, 2026.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
SimpleHelp versions 5.5.15 and earlier; 6.0 pre-release versions (fixed in 5.5.16 and 6.0 RC2)CITATIONS
- → https://thehackernews.com/2026/06/attackers-exploit-simplehelp-cve-2026.html
- → https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
- → https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- → https://hard2bit.com/en/blog/cve-2026-48558-simplehelp-oidc-bypass-taskweaver-djinn-stealer/