---
schema: 1
kind: vulnerability
title: "CVE-2026-48558 — SimpleHelp RMM: OIDC SSO authentication bypass, actively exploited"
headline: "CVE-2026-48558 — SimpleHelp RMM: OIDC SSO authentication bypass, actively exploited"
summary: "SimpleHelp RMM OIDC authentication bypass (CVE-2026-48558, CVSS 10.0) is being actively exploited to deploy the new Djinn infostealer. The server accepts forged OIDC identity tokens without verifying their signature (CWE-347), yielding a full Technician session and bypassing MFA on first OIDC login; Horizon3.ai measured ~14,000 internet-exposed instances with ~1,000 carrying a vulnerable OIDC configuration (Horizon3.ai, 2026-06-12). See the Immediate Action callout below."
discovered_at: "2026-06-30T05:10:36Z"
event_date: 2026-06-29
run_id: 2026-06-30-9aaa1114
priority: critical
immediate_action:
  title: Patch or pull internet-exposed SimpleHelp RMM now
  action: "CVE-2026-48558 (CVSS 10.0) is an OIDC SSO authentication bypass in SimpleHelp Remote Monitoring and Management: the OIDC callback handler accepts an attacker-forged identity token without verifying its cryptographic signature, granting a full Technician-level session and bypassing MFA, on any instance with an OIDC provider and group-authenticated logins enabled (Horizon3.ai, 2026-06-12). Threat actors are chaining it to deploy the new cross-platform Djinn infostealer via a \"TaskWeaver\" loader that persists through scheduled tasks / launchd plists (BleepingComputer, 2026-06-29)."
tags:
  - vulnerabilities
  - actively-exploited
  - auth-bypass
  - cisa-kev
  - infostealer
regions:
  - global
sectors:
  - technology
  - public-sector
entities: []
cves:
  - id: CVE-2026-48558
    cvss: "10.0"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/"
    publisher: Horizon3.ai
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/"
    publisher: BleepingComputer
    role: corroborating
  - url: "https://ccb.belgium.be/advisories/warning-simplehelp-patched-cve-2026-48558-critical-authentication-bypass-vulnerability"
    publisher: Centre for Cybersecurity Belgium
    role: corroborating
closed_sources: []
evidence:
  - quote: Hackers exploit critical SimpleHelp flaw to deploy new Djinn infostealer and TaskWeaver malware
    publisher: BleepingComputer
  - quote: "nearly 14,000 SimpleHelp servers exposed, with roughly 7.2% configured to use the vulnerable OIDC authentication method"
    publisher: Horizon3.ai
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-30.md
---

CVE-2026-48558 (CVSS 10.0) is an OIDC SSO authentication bypass in SimpleHelp Remote Monitoring and Management. The OIDC callback handler accepts an identity token without verifying its cryptographic signature (CWE-347), so an attacker can forge an arbitrary token and obtain a full Technician-level session; MFA is also bypassed on first OIDC login ([Horizon3.ai, 2026-06-12](https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/)). Exploitation requires the instance to have an OIDC provider configured, a TechnicianGroup bound to it, and "Allow group authenticated logins" enabled — Horizon3.ai measured ~14,000 internet-exposed servers, ~7.2% (~1,000) with a vulnerable OIDC configuration. CISA added it to the KEV catalog on 2026-06-29; the listing flag confirms active exploitation in the wild. Patched in v5.5.16 / v6.0 RC2 (vendor advisory issued May 2026). Observed follow-on: deployment of the new cross-platform Djinn infostealer via a "TaskWeaver" loader persisting through scheduled tasks (`schtasks.exe`) / launchd plists ([BleepingComputer, 2026-06-29](https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/)). Hunt: Technician logins not correlated with MFA/VPN events; `SimpleHelpServer.exe`/`SimpleHelp.exe` spawning `powershell.exe`/`cmd.exe`/`wscript.exe` (Sysmon EID 1, parent-image filter).
