Description
This module exploits CVE-2026-48558 to forge an OpenID Connect identity token and obtain a SimpleHelp technician session. It then uses SimpleHelp's legitimate remote access WebSocket protocol to connect to an online managed machine and execute a payload through the remote terminal.
An OIDC provider must be enabled for a technician group that permits group-authenticated logins. The group must be allowed to access the selected machine and run remote commands. The SimpleHelp server must have a valid session license, and at least one managed machine must be online.
SimpleHelp 5.5.0 through 5.5.15 are affected. Some SimpleHelp 6.0 prerelease builds before 6.0 RC2 are also affected.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/simplehelp/oidc_auth_bypass_rcemsf undefined(oidc_auth_bypass_rce) > show actions ...actions...msf undefined(oidc_auth_bypass_rce) > set ACTION < action-name >msf undefined(oidc_auth_bypass_rce) > show options ...show and set options...msf undefined(oidc_auth_bypass_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub