SimpleHelp Vulnerability Allows Unauthenticated Creation of Rogue Remote Support Accounts
Severity: HIGH
A security flaw in SimpleHelp remote management software enables unauthenticated attackers to create privileged technician accounts. This vulnerability affects servers configured with OpenID Connect (OIDC) authentication. Successful exploitation could grant attackers full control over remote support sessions and access to managed systems, posing a severe risk to organizations using SimpleHelp.
Source: BleepingComputer