Vulnerability record · CVE-2026-48558 · published 12 June 2026
CVE-2026-48558: SimpleHelp OIDC authentication bypass via unverified token signature
Simple Help · Simplehelp
SimpleHelp 5.5.15 and earlier and 6.0 pre-release versions accept OIDC identity tokens without verifying their cryptographic signature. When OIDC is configured, a remote unauthenticated attacker can forge a token with arbitrary identity claims and obtain a fully authenticated technician session. The flaw is rated CVSS 4.0 9.5 critical and is listed in CISA KEV.
Description
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 score of 9.5, unauthenticated remote authentication bypass to a privileged technician session, CISA KEV listing with a near-term due date, and EPSS above the 99th percentile.
What it is
SimpleHelp 5.5.15 and earlier and 6.0 pre-release versions accept OIDC identity tokens without verifying their cryptographic signature. When OIDC is configured, a remote unauthenticated attacker can forge a token with arbitrary identity claims and obtain a fully authenticated technician session. The flaw is rated CVSS 4.0 9.5 critical and is listed in CISA KEV.
Impact
An attacker gains a fully authenticated technician session, which in a remote support product typically carries broad control over managed endpoints. In some configurations this also bypasses multi-factor authentication.
Attack surface
Reachable over the network through the OIDC login flow; no authentication and no user interaction are required. It only applies where OIDC authentication is configured, matching the AT:P attack requirement in the CVSS vector.
Exploitation
Listed in CISA KEV with a 2026-07-02 remediation due date, and EPSS 30-day probability is 0.64313 (99.19th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is documented in the record.
What to do
- Upgrade SimpleHelp to a fixed release per the vendor security update and release notes; 5.5.15 and prior and 6.0 pre-release builds are affected.
- If patching cannot be done immediately, disable OIDC authentication or restrict access to the SimpleHelp instance until the fix is applied.
- Follow CISA BOD 26-04 guidance, including evaluating internet exposure of each SimpleHelp asset and discontinuing use if mitigations are unavailable.
- Review technician accounts and sessions created since exposure for unauthorized access and rotate credentials and OIDC client secrets.
- Apply the vendor's forensics triage requirements referenced in the KEV entry.
Detection
- Hunt authentication logs for technician sessions established through the OIDC flow with anomalous or unexpected identity claims.
- Review SimpleHelp access logs for logins from unfamiliar source IPs or at unusual times, especially where MFA was expected.
- Check for new or modified technician accounts and for configuration changes made after suspicious OIDC logins.
- Use the IOCs published in the Horizon3 disclosure to scan for known exploitation artifacts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-48558 to the Known Exploited Vulnerabilities catalog on 29 June 2026 as "SimpleHelp Authentication Bypass Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 2 July 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/ | Third Party Advisory |
| https://simple-help.com/release-news | Release Notes |
| https://simple-help.com/security/simplehelp-security-update-2026-05 | PatchVendor Advisory |
| https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/ | Technical DescriptionThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48558 | US Government Resource |
Track CVE-2026-48558 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-48558), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.