Security Bulletin text on the screen with a wolf in the background
Security Bulletin text on the screen with a wolf in the background

CVE-2026-48558: Critical Authentication Bypass Vulnerability in SimpleHelp RMM Exploited for Credential Theft and Malware Delivery

CVE-2026-48558 is a critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software, caused by improper validation of OpenID Connect (OIDC) token signatures.
Security Bulletin text on the screen with a wolf in the background
6 min read

Summary

CVE-2026-48558 is a critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software, caused by improper validation of OpenID Connect (OIDC) token signatures. When OIDC is configured with group-authenticated login settings, unauthenticated attackers can forge identity tokens to bypass multi-factor authentication and gain privileged technician-level access to vulnerable SimpleHelp servers — without valid credentials.

This vulnerability is particularly concerning because of SimpleHelp’s widespread adoption among managed service providers (MSPs), IT service organizations, and cloud providers. RMM platforms are designed to centralize remote access across many endpoints; a single compromised SimpleHelp server can give an attacker reach across every organization that provider manages, while making malicious activity appear to originate from a trusted source. Arctic Wolf has observed active exploitation of this vulnerability in the wild, with threat actors deploying custom malware to harvest credentials and establish persistent access across managed environments.

CISA has added CVE-2026-48558 to its catalog with a remediation deadline of July 2, 2026. Internet scans indicate approximately 14,000 SimpleHelp servers are externally exposed, with an estimated 1,000 directly vulnerable. Arctic Wolf strongly recommends immediate patching and review of the recommendations below.

Recommendations for CVE-2026-48558

Arctic Wolf strongly recommends that customers running SimpleHelp server software upgrade to the latest fixed version immediately. CISA has added CVE-2026-48558 to its Known Exploited Vulnerabilities (KEV) catalog with a July 2, 2026 remediation deadline. See SimpleHelp’s security advisory and updating guide for step-by-step instructions.

Product Affected Version Fixed Version
SimpleHelp server 5.5.x (prior to 5.5.16) 5.5.16
SimpleHelp server 6.0 pre-release 6.0 RC2 / final

 

Organizations using OIDC authentication with group-authenticated logins should disable OIDC immediately on any server that cannot be patched right away (Administration ➔ Login Security), and restrict internet-facing access via firewall or VPN until the upgrade is complete.

Please follow your organization’s patching and testing guidelines to minimize potential operational impact.

Immediate Actions

  • Isolate if upgrade is not immediately possible: Temporarily disconnect affected SimpleHelp servers from the internet or stop SimpleHelp services until the server can be patched.
  • Restrict network access: Use firewall, VPN, or application gateway rules to limit SimpleHelp web access to trusted IPs and networks only. Enforce IP allowlisting for technician logins within SimpleHelp’s Login Security settings.
  • Audit technician accounts: Review SimpleHelp’s internal technician roster for unauthorized or unexpected entries — especially recently created accounts or those tied to unfamiliar email addresses. This review requires SimpleHelp administrator access.
  • Review server logs: Inspect SimpleHelp server logs for OIDC login bypass attempts, unexpected technician registrations, or configuration changes outside normal patterns. SimpleHelp application logs may not be forwarded to external monitoring platforms by default. Continue reviewing logs regularly until patching is complete.

Limitations: Disabling OIDC will impact SSO and federated identity workflows. Restricting network access may disrupt remote support capabilities. These measures are temporary — complete patching as soon as possible.

Long-Term Measures

  • Eliminate direct internet exposure for all RMM tools; enforce zero-trust and least-privilege access models.
  • Establish rapid patch-management workflows and incident response playbooks for RMM platforms.
  • Periodically audit authentication provider integrations (OIDC, OAuth, SAML) for proper token validation and security practices.
  • If your organization operates additional security monitoring tools outside of Arctic Wolf, consider deploying detection rules for the IOCs referenced in this bulletin.

References

Share this post: