← All Advisories

CVE-2026-48558: SimpleHelp Authentication

Status: KEV  |  Advisory ID: CVE-2026-48558

Key Details

CVECVE-2026-48558
Affected productsSimpleHelp SimpleHelp
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-347 (Improper Verification of Cryptographic Signature)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-06-29.
Exploitation prediction (EPSS)64% probability of exploitation in the next 30 days (99% percentile) -- FIRST.org's EPSS model.
Federal remediation deadline2026-07-02 (CISA KEV, Binding Operational Directive).

What to Know

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-48558