Status: KEV | Advisory ID: CVE-2026-48558
| CVE | CVE-2026-48558 |
| Affected products | SimpleHelp SimpleHelp |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-347 (Improper Verification of Cryptographic Signature) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-06-29. |
| Exploitation prediction (EPSS) | 64% probability of exploitation in the next 30 days (99% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-07-02 (CISA KEV, Binding Operational Directive). |
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-48558 |