LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-48558: SimpleHelp Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 29, 2026
CVSS 9.5 · Critical⚠ Actively exploited (CISA KEV)
9.5
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Jul 2, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-48558 to its Known Exploited Vulnerabilities catalog on Jun 29, 2026, with a federal patch deadline of Jul 2, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

SimpleHelp contains an authentication bypass vulnerability in its OIDC authentication flow. When OIDC is enabled, the product accepts identity tokens during login without verifying their cryptographic signature. A remote unauthenticated attacker can therefore submit a forged token with arbitrary claims and obtain a fully authenticated technician session; in some setups this also bypasses multi-factor authentication.

How it works

The flaw belongs to CWE-347, improper verification of cryptographic signatures. In the OIDC login path the application receives an identity token but does not check the signature that should prove the token was issued by the configured identity provider. An attacker who can reach the login endpoint can therefore craft a token containing any desired identity claims and present it as valid.

Because the bypass occurs at the point of token acceptance, the resulting session carries whatever privileges are mapped to those claims, including technician access. The vulnerability is configuration-dependent and only affects deployments that have turned on OIDC authentication.

Am I affected? How to find it in your systems

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, re-verify that OIDC tokens are now validated according to the identity provider’s requirements and that multi-factor authentication remains enforced where configured.

If you can't patch immediately

If your data may have been exposed

Authentication bypass vulnerabilities that are actively exploited can lead to unauthorized access and subsequent data exposure. You can run a free exposure scan of your email addresses against known breach data to check for signs of prior compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSimpleHelp · SimpleHelp
WeaknessCWE-347
CVSS base score9.5 (Critical)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedJun 12, 2026
Added to CISA KEVJun 29, 2026
Federal patch deadlineJul 2, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities