CVE-2026-48558 CRITICAL

SimpleHelp SimpleHelp Vulnerability
Generated: 10 Oct 2026 19:56 • CVE Threat Intelligence

Description

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

9.8
CVSS CRITICAL

Details

Published
29 Jun 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
SimpleHelp
Product
SimpleHelp
Fix Version
Vendor Patch / Mitigation Available