CVE-2026-48558: SimpleHelp Authentication Bypass Vulnerability
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
Other sources
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48558?
CVE-2026-48558 is rated as critical with a base score of 10.
How do I fix CVE-2026-48558?
To mitigate CVE-2026-48558, upgrade to SimpleHelp version 5.5.16 or later, or 6.0 stable release.
What systems are affected by CVE-2026-48558?
CVE-2026-48558 affects SimpleHelp versions 5.5.15 and prior, as well as pre-release versions of 6.0.
What is the nature of the vulnerability in CVE-2026-48558?
CVE-2026-48558 is an authentication bypass vulnerability that allows accepting identity tokens without verifying their JWT signature.
When was CVE-2026-48558 published?
CVE-2026-48558 was published on June 12, 2026.