:

SIMPLEHELP BUG LETS ATTACKERS CREATE ADMIN ACCOUNTS

SECURITY DESK2 MIN READ
MON, JUN 15, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A vulnerability in SimpleHelp remote management software allows unauthenticated attackers to create privileged technician accounts on vulnerable servers. The flaw exploits the OpenID Connect (OIDC) authentication protocol.

SimpleHelp, a remote support and management platform, contains a critical authentication bypass vulnerability that could allow attackers to gain administrative access without credentials. The vulnerability enables unauthenticated threat actors to create new technician accounts with elevated privileges on affected SimpleHelp servers. By exploiting improper OIDC implementation, attackers can bypass authentication checks entirely. Attack Vector The flaw resides in how SimpleHelp handles OIDC authentication flows. OIDC is a standard protocol for delegated authentication, but improper implementation can introduce security gaps. In this case, attackers can craft requests that the server accepts as legitimate, granting them technician-level access. Once authenticated as a technician, attackers gain remote management capabilities. This could allow them to access customer systems, install malware, steal data, or maintain persistent backdoors. Impact SimpleHelp serves MSPs (Managed Service Providers) and IT departments that rely on the platform for remote support operations. A compromised SimpleHelp instance could expose all connected client systems to attackers. The vulnerability affects organizations across industries, from small IT shops to larger enterprises using SimpleHelp for managed services. Remediation SimpleHelp has released patches addressing the authentication flaw. The vendor recommends immediate updates for all affected installations. Administrators should: - Update SimpleHelp to the patched version immediately - Review account logs for unauthorized technician accounts - Audit recent remote sessions for suspicious activity - Monitor for unauthorized access attempts Organizations that cannot patch immediately should restrict network access to SimpleHelp servers and review authentication logs closely. Context This vulnerability underscores risks in remote management tools, which are high-value targets for attackers seeking access to multiple customer systems simultaneously. Proper authentication implementation remains critical for tools handling privileged access.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A proof-of-concept attack called BragJack can hijack AI assistants across multiple browsers and platforms through a single malicious extension. Security researcher Gal Weizman from Forever Security demonstrated the vulnerability using a Prompt Forcing technique.

1H AGOAI Desk

Law enforcement agencies have issued a joint advisory detailing a sustained campaign by the North Korean hacking group WaterPlum, which compromised at least 30,000 devices worldwide and stole over $10.7 million in cryptocurrency between December 2025 and July 2026.

1H AGOSecurity Desk

If your PC is running slowly or behaving unusually, malware may be the culprit. Running a malware check is a straightforward way to diagnose and address the problem.

2H AGOSecurity Desk

A detailed investigation revealed that smart TVs from major manufacturers collect extensive user data, including audio recordings and viewing habits, even when devices appear powered off. The practice extends across the industry, not limited to LG.

2H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.