LOWVulnerability
CVE-2026-48558
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
Properties
- product
- SimpleHelp
- vulnerabilityName
- SimpleHelp Authentication Bypass Vulnerability
- epss_score
- 0.11484
- cve_id
- CVE-2026-48558
- dueDate
- 2026-07-02
- vendorProject
- SimpleHelp
- requiredAction
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
- dateAdded
- 2026-06-29
- epss_percentile
- 0.95623
Related Entities (5)
MENTIONED_IN (2)
→[Campaign]Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection
→[Campaign]A Djinn in the Machine: TaskWeaver's Node.js Intrusion Chain
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBES (1)
←[KEVEntry]SimpleHelp Authentication Bypass Vulnerability
KNOWN_EXPLOITED (1)
→[Source]CISA KEV
Explore deeper with Ninja Signal's threat intelligence graph