Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-48558: SimpleHelp OIDC Authentication Bypass in Older Versions
Known exploited
CVE-2026-48558
CVE-2026-48558
CVE-2026-48558
Summary
Old versions of SimpleHelp allow hackers to access the system without a password. This happens when the system uses a specific authentication method. To fix this, update to the latest version of SimpleHelp.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| simplehelp | simplehelp | All versions |
| simple-help | simplehelp |
< 5.5.16 6.0 cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:* |
| simplehelp | simplehelp | < 5.5.16 |
Original title
SimpleHelp Authentication Bypass Vulnerability
Original description
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
nvd CVSS3.1
10.0
nvd CVSS4.0
9.5
Vulnerability type
CWE-347
Improper Verification of Cryptographic Signature
- https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intr...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-...
- https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authen...
- https://simple-help.com/release-news
- https://simple-help.com/security/simplehelp-security-update-2026-05
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 12 Jun 2026