Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical SimpleHelp Auth Bypass Exposes 14, Nearly Servers
June 16, 2026
Microsoft Site Warning: Certificate Expiry Causes Issues
June 15, 2026
SHADOWBYT3$ Claims Nintendo Breach, Sensitive Data
June 15, 2026
Home/CyberSecurity News/Critical SimpleHelp Auth Bypass Exposes 14, Nearly Servers
CyberSecurity News

Critical SimpleHelp Auth Bypass Exposes 14, Nearly Servers

The disclosure of a critical authentication bypass vulnerability, tracked as CVE-2026-48558, has left nearly 14,000 internet-facing SimpleHelp servers exposed. The flaw raises serious concerns for...

Marcus Rodriguez
Marcus Rodriguez
June 16, 2026 3 Min Read
3 0

The disclosure of a critical authentication bypass vulnerability, tracked as CVE-2026-48558, has left nearly 14,000 internet-facing SimpleHelp servers exposed.

The flaw raises serious concerns for enterprises using the remote monitoring and management (RMM) platform.

Horizon3.ai identified the vulnerability through its autonomous research initiative “Sua Sponte,” which leverages AI-driven analysis to uncover exploitable flaws.

The issue affects SimpleHelp deployments configured with OpenID Connect (OIDC) authentication, including integrations with Azure Active Directory.

CVE-2026-48558 is caused by improper validation of identity provider assertions during the OIDC authentication process.

This flaw allows unauthenticated attackers to create a new “Technician” account and log in without valid credentials.

SimpleHelp Servers Exposed by Auth Bypass

Once inside, the attacker gains elevated privileges, as technician accounts can access managed endpoints, execute scripts, and perform administrative actions. Even environments protected by multi-factor authentication are not immune.

The vulnerability enables attackers to bypass MFA by registering their own authentication method during the first login, effectively nullifying this security layer.

Indicators of Compromise ( source : horizon3.ai)
Indicators of Compromise ( source : horizon3.ai)

The issue becomes exploitable in environments where OIDC authentication is enabled, a TechnicianGroup is linked to the OIDC provider, and group-authenticated logins are permitted.

These settings are commonly found in enterprise deployments, increasing the likelihood of exploitation in real-world scenarios.

To detect potential compromise, administrators should carefully review technician accounts within the SimpleHelp interface, specifically checking for unfamiliar names or email addresses.

Server logs should also be analyzed for suspicious activity, such as unauthorized technician registrations or unexpected configuration changes.

Log files stored on the host system, including those in the /opt/SimpleHelp/logs/ directory, may provide additional evidence of malicious activity.

The scale of exposure has grown significantly over the past year. Horizon3.ai reports that the number of publicly accessible SimpleHelp servers has increased from around 3,400 in early 2025 to nearly 14,000 as of June 2026.

Further analysis suggests that approximately 7.2% of these systems are configured in a way that makes them vulnerable to this authentication bypass.

Given SimpleHelp’s role in remote access and endpoint management, successful exploitation could allow attackers to move laterally across networks and compromise critical systems.

Organizations are strongly advised to apply the latest security updates released by SimpleHelp to remediate the vulnerability.

SimpleHelp offers optional settings to enhance Technician login security( source : horizon3.ai)
SimpleHelp offers optional settings to enhance Technician login security( source : horizon3.ai)

In cases where immediate patching is not possible, administrators should implement temporary controls, such as restricting technician login access based on IP address in the platform’s security settings.

The vulnerability was discovered on May 21, 2026, reported to the vendor the following day, and publicly disclosed on June 12, 2026. A patch was released on June 9, before the public advisory.

This disclosure underscores the ongoing risks associated with widely deployed RMM tools. It highlights the importance of securing authentication mechanisms, particularly when integrating with enterprise identity providers.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Microsoft Site Warning: Certificate Expiry Causes Issues

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Anthropic Updates Privacy Policy: Claude Users Need ID Verify
June 15, 2026
Hackers Use Microsoft Graph Reconnaissance to Target Payroll and
June 15, 2026
China-Nexus Hackers Exploit PAM Modules Backdoored Credential
June 15, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us