socradar.io 6/30/2026, 10:44:19 AM · external

SimpleHelp auth bypass lets hackers deploy Djinn Stealer

SimpleHelp auth bypass lets hackers deploy Djinn Stealer
Developing story vulnerability 7 articles tracked
SimpleHelp authentication bypass (CVE-2026-48558) exploited to deploy TaskWeaver and Djinn Stealer
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CVE- 2026-48558 is a critical vulnerability in SimpleHelp, a remote monitoring and management platform, allowing authentication bypass and potential infostealer payload deployment. This flaw arises from improper verification of cryptographic signatures for OpenID Connect (OIDC) during technician logins, particularly affecting versions 5.5.1 to 5.5.15 and pre-release versions of 6.0. Active exploitation has been confirmed, linked to an intrusion chain using a tool called Djinn Stealer to steal credentials and tokens.

CISA has prioritized this issue, requiring immediate patching and risk mitigation, including restrictions to technician login and credential hygiene to protect against downstream attacks.

View Primary Source Via socradar.io

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline