---
schema: 1
kind: vulnerability
title: "CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session"
headline: "CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session"
summary: "SimpleHelp RMM ships an unauthenticated OIDC auth-bypass (CVE-2026-48558). A forged unsigned OIDC token yields a full technician session and bypasses IdP MFA — a clean initial-access vector into every downstream MSP-managed estate (Horizon3.ai, 2026-06-12)."
discovered_at: "2026-06-13T05:00:03Z"
event_date: 2026-06-12
run_id: 2026-06-13-40b26572
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - pre-auth
  - poc-public
  - patch-available
regions:
  - global
  - europe
sectors:
  - technology
entities:
  - "actor:shinyhunters"
cves:
  - id: CVE-2026-48558
    cvss: n/a
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/"
    publisher: Horizon3.ai
    role: primary
  - url: "https://simple-help.com/security/simplehelp-security-update-2026-05"
    publisher: SimpleHelp
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch SimpleHelp to 5.5.16 / 6.0 RC2, or disable OIDC** — CVE-2026-48558 lets an unauthenticated attacker forge an OIDC token into a full Technician session and bypass IdP MFA; review access logs for no-signature token exchanges preceding successful Technician auth (."
migrated_from: briefs/2026-06-13.md
---

SimpleHelp, a self-hosted remote-support/RMM platform common in European MSP estates, fails to verify the cryptographic signature of OIDC identity tokens presented at login when OIDC authentication is enabled ([Horizon3.ai, 2026-06-12](https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/)). A remote, unauthenticated attacker who submits a forged, unsigned token carrying arbitrary identity claims obtains a fully authenticated Technician session with no user interaction; because signature verification is skipped entirely, any MFA enforced at the identity provider is also bypassed. SimpleHelp patched it in versions 5.5.16 and the 6.0 RC2 prerelease (Security Notice 2026-05); servers running 5.5.15 and earlier are affected ([SimpleHelp, 2026-06-12](https://simple-help.com/security/simplehelp-security-update-2026-05)). Horizon3 published detection IOCs for post-exploitation in MSP environments; neither the vendor notice nor the Horizon3 disclosure states a CVSS score at the time of writing. Maps to T1190 (Exploit Public-Facing Application) and T1078.004 (Valid Accounts). Technician access to an RMM server is a stepping stone into every downstream client estate, which is why MSP-tooling auth bypasses are a recurring initial-access vector. Detection: review SimpleHelp access logs for successful Technician authentications preceded by malformed/no-signature OIDC token exchanges and for new Technician sessions from unfamiliar source ranges. Hardening: patch immediately; until then disable OIDC and require SAML or local auth with MFA, and network-restrict the web interface.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-48558 | SimpleHelp RMM (OIDC auth) | n/a | n/a | No | No (research PoC) | 5.5.16 / 6.0 RC2 | [Horizon3.ai](https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/) |
| CVE-2026-35273 | Oracle PeopleSoft PeopleTools (PSEMHUB) | 9.8 | n/a | Yes (2026-06-12) | Yes (UNC6240, 27 May) | OOB patch 2026-06-10 (8.61/8.62) | [Mandiant/GTIG](https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/) |

*(CVE-2026-35273 carried as § 4 UPDATE; included here for the gate-clearing exploitation picture. CVEs that did not clear a § 2 inclusion gate — GitLab CVE-2026-6552 and the Check Point LangGraph chain — are noted in § 3 / § 7.)*
