Support Knowledgebase
NAV

Security Vulnerability affecting SimpleHelp 5.5.15 and earlier, and some pre-release versions of 6.0

Servers on versions 5.5.15 and earlier, and some 6.0 pre-release versions which have: - An OIDC Authentication Service is configured and enabled (In Administration; Authentication Services, the OIDC-based categories are labelled Active Directory, Azure and OpenID Connect) - One or more Technician Groups where a user has configured and enabled both: - An OIDC Authentication Service in the Group's Authentication tab - Allow group authenticated logins in the Group's General Properties tab (this is disabled by default for new Groups)

May be vulnerable to an exploit that can allow an attacker able to connect to a server from an IP address permitted by a server's Technician login IP restrictions to authenticate (provided the attempt satisfies all filters for that Authentication Service in the Group's Authentication tab), and generate a new Technician account, then log in as that user with the permissions granted by applicable Technician Groups. Existing Technician accounts may have their Authentication User IDs set to invalid values causing duplicate account creation.

Servers that do not use OIDC authentication, and those that do but do not have any Groups using OIDC authentication with Allow group authenticated logins enabled cannot be exploited this way. Technician login IP restrictions will block the login if it originates from excluded IP ranges. Authentication filters must also be satisfied for the attempt to succeed.

SimpleHelp versions 5.5.16 and the upcoming final release of 6.0 and later are not affected and cannot be exploited. Some 6.0 beta and release candidate builds are affected, and should be updated to the latest 6.0 release candidate.

This vulnerability is registered under CVE-2026-48558.

Suggested Action Summary

If in doubt, disconnect your SimpleHelp server from the network or stop the process until you have fully read and understood the guidance below and taken any appropriate steps.

  1. If you are running an affected version, update to a secure version as soon as possible. These are available here: https://simple-help.com/security/simplehelp-security-update-2026-05

  2. Refer to the Server Vulnerability, Impacts of Compromise and Characteristics of Compromise sections below for guidance about this vulnerability.

  3. Read our security guide and take any recommended measures you haven't already to ensure your server is secure.

Ensure your account on our site has up to date email information, and that the email's inbox is regularly monitored and is not filtering email from us to receive critical security advisories and other legitimate interest communications. Log into your account on our site (at https://simple-help.com/account), go to the Privacy tab and activate the toggle next to Mailing List to opt in to new release notifications and other strictly product-relevant messaging as well.

Please contact us with any queries, or if you need more information.

Updating

Secure version installers are available on our security notice page.

Updating to 5.5.16

When updating any 5.5 version to 5.5.16 the usual update guidance applies. If version 6.0 is the latest release on the download page and you cannot or do not wish to update to 6.0, contact us.

Updating to 6.0

If your production server is running a 5.5 version and the final public release of 6.0 is still pending we recommend updating to 5.5.16 rather than a 6.0 pre-release version.

If you are running a pre-release 6.0 version, update to the latest pre-release version available on the pre-release page here.

Note: - To run version 6.0 your server will need to be linked to our site to fetch your license. See this section of the Administration guide. If your server cannot connect to ours, contact us. - Rolling back from 6.0 to 5.5 is not supported and running a 5.5 installer as usual to roll back will not work: Make a complete backup of your SimpleHelp installation on the prior version before updating to give you the ability to reinstate your server on the earlier version if you encounter problems with 6.0.

Updating from earlier versions of SimpleHelp

If you are running a version of SimpleHelp older than 5.5.0, contact us.

Server Vulnerability

SimpleHelp servers on 5.5.16, the public 6.0 release or later versions are not subject to this vulnerability.

Servers on 5.5.15 and earlier, and early 6.0 pre-release builds (beta and release candidates) are vulnerable if all of the following are true: - An OIDC Authentication Service is configured and enabled in Administration; Authentication Services. - One or more Technician Groups have both: - An enabled OIDC Authentication Service in the Authentication tab. - Allow group authenticated logins enabled in the General Properties tab.

To exploit a server an attacker must be able to connect to it: Servers accessible only from local networks or recognised and trusted IP ranges are at much lower risk of exploitation.

To log in as a Technician the attacker must be connecting from an IP address permitted by Technician login IP restrictions.

The attempt must also satisfy all filters configured for the Authentication Service in the Group's Authentication tab.

Impact of Compromise

An attacker able to connect to your server from an IP permitted by Technician IP login filters may be able to log in as a Technician. The full potential impact then depends on the limitations configured for and permissions granted to Technician accounts, for example the ability to start sessions to machines, create and run scripts. The most severe case would be if the attacker gains access to a Technician with server admin privileges, in which case cybersecurity expert assistance would be required to determine the full extent of compromise and perform any remediation. Without server or group admin privileges, an attacker might still be able to steal data from or install malware on connected machines.

Characteristics of Compromise

Unexpected Technician account creation and activity, logins, sessions, Tool runs, especially from unrecognised IP addresses. These are still bound by the limitations placed on them by their machine and customer filters, Technician Groups' permissions, filters and limitations, and server rules such as Technician login IPs. If any anomalies are noted while the server is running an insecure release, especially among users with powerful permissions such as group and server admins that may be able to configure server configuration, take immediate action to isolate the server and seek cybersecurity expert assistance.

Sources of information:

  • Server logs: Technician logins are recorded here along with the IP the login came from the Technician account involved, the Technician Groups the account is a member of (thus their privileges granted to them by their Groups). In particular, lines containing New Anon within an OIDC login flow indicate a new account created by Allow group authenticated logins and should be verified.
  • Administration; Technicians. Check the list of Technician accounts here (use the cog button to check Show Group Authenticated Users to show all accounts) and verify their Group memberships, their login and enabled status.
  • Administration; History. Sessions are recorded here.

If any anomalies are noted while the server is running an insecure release, especially among users with powerful permissions such as group and server admins that may be able to configure server configuration, take immediate action to isolate the server and seek cybersecurity expert assistance.

Send us your Questions

Please contact us with any queries, or if you need more information.