Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-48558: SimpleHelp OIDC Authentication Bypass in Older Versions

Known exploited
CVE-2026-48558 CVE-2026-48558 CVE-2026-48558
Summary

Old versions of SimpleHelp allow hackers to access the system without a password. This happens when the system uses a specific authentication method. To fix this, update to the latest version of SimpleHelp.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
simplehelp simplehelp All versions
simple-help simplehelp < 5.5.16
6.0
cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:*
simplehelp simplehelp < 5.5.16
Original title
SimpleHelp Authentication Bypass Vulnerability
Original description
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
nvd CVSS3.1 10.0
nvd CVSS4.0 9.5
Vulnerability type
CWE-347 Improper Verification of Cryptographic Signature
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 12 Jun 2026