Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-48558

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

View on NVD

Analysis

Las versiones 5.5.15 y anteriores de SimpleHelp permiten que atacantes remotos no autenticados eviten el proceso de inicio de sesión mediante el envío de tokens OIDC falsificados sin verificación de firma. Esta vulnerabilidad otorga acceso completo con privilegios de técnico y puede saltarse la autenticación de dos factores, comprometiendo totalmente la infraestructura de soporte remoto.

Relevant roles

BackendCyberSecurityWindowsLinuxCloud

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-347

EPSS

Probability of exploitation (next 30 days): 0.0063 (0.6%)
Percentile: 45.1%
EPSS: 2026-06-15

Technical description

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

Published: 6/12/2026, 6:16:35 PM
Last modified: 6/12/2026, 6:16:35 PM

References

HomeEventsBlogResourcesTeam