ctipilot.ch

SimpleHelp RMM OIDC SSO auth bypass — forged-token full Technician session + MFA bypass; now actively exploited (CISA KEV 2026-06-29), Djinn infostealer via TaskWeaver loader (CVSS 10.0)

cve · CVE-2026-48558

Coverage timeline
2
first 2026-06-13 → last 2026-06-30
Peak priority
critical
1 critical · 1 high
Sources cited
5
5 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
1
see Related entities below
ATT&CK techniques
2
pinned v19.1 · see below

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · ATT&CK page ↗

Story timeline

  1. 2026-06-30CVE-2026-48558 — SimpleHelp RMM: OIDC SSO authentication bypass, actively exploited
    trending-vulnerabilities
  2. 2026-06-13CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities2

Source distribution

  • bleepingcomputer.com1 (20%)
  • ccb.belgium.be1 (20%)
  • cloud.google.com1 (20%)
  • horizon3.ai1 (20%)
  • simple-help.com1 (20%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about SimpleHelp RMM OIDC SSO auth bypass — forged-token full Technician session + MFA bypass; now actively exploited (CISA KEV 2026-06-29), Djinn infostealer via TaskWeaver loader (CVSS 10.0) (2)

2026-06-30 · view entry permalink →

CRITICALCVE-2026-48558exploited

CVE-2026-48558 — SimpleHelp RMM: OIDC SSO authentication bypass, actively exploited

CVE-2026-48558 (CVSS 10.0) is an OIDC SSO authentication bypass in SimpleHelp Remote Monitoring and Management. The OIDC callback handler accepts an identity token without verifying its cryptographic signature (CWE-347), so an attacker can forge an arbitrary token and obtain a full Technician-level session; MFA is also bypassed on first OIDC login (Horizon3.ai, 2026-06-12). Exploitation requires the instance to have an OIDC provider configured, a TechnicianGroup bound to it, and "Allow group authenticated logins" enabled — Horizon3.ai measured ~14,000 internet-exposed servers, ~7.2% (~1,000) with a vulnerable OIDC configuration. CISA added it to the KEV catalog on 2026-06-29; the listing flag confirms active exploitation in the wild. Patched in v5.5.16 / v6.0 RC2 (vendor advisory issued May 2026). Observed follow-on: deployment of the new cross-platform Djinn infostealer via a "TaskWeaver" loader persisting through scheduled tasks (schtasks.exe) / launchd plists (BleepingComputer, 2026-06-29). Hunt: Technician logins not correlated with MFA/VPN events; SimpleHelpServer.exe/SimpleHelp.exe spawning powershell.exe/cmd.exe/wscript.exe (Sysmon EID 1, parent-image filter).

Hackers exploit critical SimpleHelp flaw to deploy new Djinn infostealer and TaskWeaver malware

BleepingComputer

nearly 14,000 SimpleHelp servers exposed, with roughly 7.2% configured to use the vulnerable OIDC authentication method

Horizon3.ai
vulnerability30 Jun 05:10Zmulti-sourceOpen finding ↗

2026-06-13 · view entry permalink →

CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session

SimpleHelp, a self-hosted remote-support/RMM platform common in European MSP estates, fails to verify the cryptographic signature of OIDC identity tokens presented at login when OIDC authentication is enabled (Horizon3.ai, 2026-06-12). A remote, unauthenticated attacker who submits a forged, unsigned token carrying arbitrary identity claims obtains a fully authenticated Technician session with no user interaction; because signature verification is skipped entirely, any MFA enforced at the identity provider is also bypassed. SimpleHelp patched it in versions 5.5.16 and the 6.0 RC2 prerelease (Security Notice 2026-05); servers running 5.5.15 and earlier are affected (SimpleHelp, 2026-06-12). Horizon3 published detection IOCs for post-exploitation in MSP environments; neither the vendor notice nor the Horizon3 disclosure states a CVSS score at the time of writing. Maps to T1190 (Exploit Public-Facing Application) and T1078.004 (Valid Accounts). Technician access to an RMM server is a stepping stone into every downstream client estate, which is why MSP-tooling auth bypasses are a recurring initial-access vector. Detection: review SimpleHelp access logs for successful Technician authentications preceded by malformed/no-signature OIDC token exchanges and for new Technician sessions from unfamiliar source ranges. Hardening: patch immediately; until then disable OIDC and require SAML or local auth with MFA, and network-restrict the web interface.

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-48558 SimpleHelp RMM (OIDC auth) n/a n/a No No (research PoC) 5.5.16 / 6.0 RC2 Horizon3.ai
CVE-2026-35273 Oracle PeopleSoft PeopleTools (PSEMHUB) 9.8 n/a Yes (2026-06-12) Yes (UNC6240, 27 May) OOB patch 2026-06-10 (8.61/8.62) Mandiant/GTIG

(CVE-2026-35273 carried as § 4 UPDATE; included here for the gate-clearing exploitation picture. CVEs that did not clear a § 2 inclusion gate — GitLab CVE-2026-6552 and the Check Point LangGraph chain — are noted in § 3 / § 7.)

vulnerability13 Jun 05:00Zmulti-sourceOpen finding ↗