Multiple outlets report a critical security vulnerability in SimpleHelp remote monitoring and management (RMM) software, tracked as CVE-2026-48558. The issue affects SimpleHelp deployments that use OpenID Connect (OIDC) for authentication. Researchers describe an authentication-bypass condition that lets an unauthenticated attacker remotely create a new “Technician” account with elevated privileges.
Once such an account is created, the attacker can use it to access managed endpoints through SimpleHelp’s remote support functions. Reported capabilities include logging into endpoints and performing actions such as executing scripts, depending on the permissions associated with the forged technician account.
One source notes that even if the SimpleHelp server is configured to require multi-factor authentication (MFA) for technician accounts, exploitation can still succeed under the vulnerable configuration using OIDC. The reports emphasize remote exploitability, meaning attackers do not need existing credentials. The overall impact described across sources is the potential for attackers to gain full control of systems managed by affected SimpleHelp instances.