LOWVulnerability

CVE-2026-48558

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

Properties

product
SimpleHelp
vulnerabilityName
SimpleHelp Authentication Bypass Vulnerability
epss_score
0.11484
cve_id
CVE-2026-48558
dueDate
2026-07-02
vendorProject
SimpleHelp
requiredAction
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
dateAdded
2026-06-29
epss_percentile
0.95623

Related Entities (5)

MENTIONED_IN (2)

[Campaign]Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection
[Campaign]A Djinn in the Machine: TaskWeaver's Node.js Intrusion Chain

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBES (1)

[KEVEntry]SimpleHelp Authentication Bypass Vulnerability

KNOWN_EXPLOITED (1)

[Source]CISA KEV

Explore deeper with Ninja Signal's threat intelligence graph