← Vulnerability feed

Vulnerability record · CVE-2026-48558 · published 12 June 2026

CVE-2026-48558: SimpleHelp OIDC authentication bypass via unverified token signature

Simple Help · Simplehelp

SimpleHelp 5.5.15 and earlier and 6.0 pre-release versions accept OIDC identity tokens without verifying their cryptographic signature. When OIDC is configured, a remote unauthenticated attacker can forge a token with arbitrary identity claims and obtain a fully authenticated technician session. The flaw is rated CVSS 4.0 9.5 critical and is listed in CISA KEV.

9.5 CVSS 4.0 Critical CISA KEV since 29 Jun 2026 EPSS 5.7% · top 7.2% CWE-347 · Improper verification of cryptographic signature
9.5CVSS 4.0 base score
5.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
30 Jun 2026Last modified by NVD

Description

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 score of 9.5, unauthenticated remote authentication bypass to a privileged technician session, CISA KEV listing with a near-term due date, and EPSS above the 99th percentile.

What it is

SimpleHelp 5.5.15 and earlier and 6.0 pre-release versions accept OIDC identity tokens without verifying their cryptographic signature. When OIDC is configured, a remote unauthenticated attacker can forge a token with arbitrary identity claims and obtain a fully authenticated technician session. The flaw is rated CVSS 4.0 9.5 critical and is listed in CISA KEV.

Impact

An attacker gains a fully authenticated technician session, which in a remote support product typically carries broad control over managed endpoints. In some configurations this also bypasses multi-factor authentication.

Attack surface

Reachable over the network through the OIDC login flow; no authentication and no user interaction are required. It only applies where OIDC authentication is configured, matching the AT:P attack requirement in the CVSS vector.

Exploitation

Listed in CISA KEV with a 2026-07-02 remediation due date, and EPSS 30-day probability is 0.64313 (99.19th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is documented in the record.

What to do

  • Upgrade SimpleHelp to a fixed release per the vendor security update and release notes; 5.5.15 and prior and 6.0 pre-release builds are affected.
  • If patching cannot be done immediately, disable OIDC authentication or restrict access to the SimpleHelp instance until the fix is applied.
  • Follow CISA BOD 26-04 guidance, including evaluating internet exposure of each SimpleHelp asset and discontinuing use if mitigations are unavailable.
  • Review technician accounts and sessions created since exposure for unauthorized access and rotate credentials and OIDC client secrets.
  • Apply the vendor's forensics triage requirements referenced in the KEV entry.

Detection

  • Hunt authentication logs for technician sessions established through the OIDC flow with anomalous or unexpected identity claims.
  • Review SimpleHelp access logs for logins from unfamiliar source IPs or at unusual times, especially where MFA was expected.
  • Check for new or modified technician accounts and for configuration changes made after suspicious OIDC logins.
  • Use the IOCs published in the Horizon3 disclosure to scan for known exploitation artifacts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-48558 to the Known Exploited Vulnerabilities catalog on 29 June 2026 as "SimpleHelp Authentication Bypass Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 2 July 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-48558 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2024-57726SimpleHelp missing authorization lets low-privilege technicians escalate to adminSimpleHelp remote support software v5.5.7 and earlier fails to properly authorize API key creation, allowing low-privilege technicians to mint API ke…KEVEPSS 67%analysed7.5CVE-2024-57727SimpleHelp path traversal allows unauthenticated file downloadSimpleHelp remote support software v5.5.7 and earlier contains multiple path traversal flaws that let unauthenticated remote attackers download arbit…KEVEPSS 97%analysed7.2CVE-2024-57728SimpleHelp zip slip path traversal allows arbitrary file write and code executionSimpleHelp remote support software v5.5.7 and earlier lets admin users upload a crafted zip file that writes files anywhere on the file system via zi…KEVEPSS 65%analysed8.8CVE-2025-36727Simple-help simplehelp inclusion from untrusted sphere vulnerabilityInclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.EPSS 0.42%8.8CVE-2025-36728Simple-help simplehelp cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.EPSS 0.17%10.0CVE-2026-5430Wso2 api control plane improper verification of cryptographic signature vulnerabilityThe JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t…KEVEPSS 0.59%9.8CVE-2025-59718Fortinet FortiOS/FortiProxy SAML signature check bypass in FortiCloud SSOFortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An un…KEVEPSS 68%analysed4.6CVE-2025-47827IGEL OS Secure Boot bypass via improper signature verificationIGEL OS before version 11 fails to properly verify a cryptographic signature in the igel-flash-driver module, allowing Secure Boot to be bypassed. A …KEVEPSS 4.9%analysed

Source: NIST National Vulnerability Database (record CVE-2026-48558), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.