{"id":"CVE-2026-48558","title":"SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow","summary":"SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted…","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-347"],"vendor":"simple-help","product":"simplehelp","affected":["simplehelp < 5.5.16","simplehelp = 6.0"],"patched":["simplehelp 5.5.16"],"published":"2026-06-12","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:17:12.940","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48558","references":[{"url":"https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/","label":"disclosure@vulncheck.com"},{"url":"https://simple-help.com/release-news","label":"disclosure@vulncheck.com"},{"url":"https://simple-help.com/security/simplehelp-security-update-2026-05","label":"disclosure@vulncheck.com"},{"url":"https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48558","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-06-30T03:55:22.397894Z"},"epss":0.05719,"epssPercentile":0.9282,"kev":true,"kevDateAdded":"2026-06-29","kevDueDate":"2026-07-02","kevRansomware":false,"exploits":{"github":1,"githubRepos":["https://github.com/J4ck3LSyN-Gen2/CVE-2026-48558"],"metasploit":["exploit/multi/http/simplehelp_oidc_auth_bypass_rce"],"nuclei":["CVE-2026-48558"],"checkedAt":"2026-10-07T20:47:22.833Z"},"ingestedAt":"2026-10-07T20:46:46.955Z","slug":"CVE-2026-48558","body":"## Overview\n\nSimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.\n\n## Affected\n\n- `simplehelp < 5.5.16`\n- `simplehelp = 6.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `simplehelp 5.5.16`","depth":"hadal","depthScore":81,"depthScoreParts":{"impact":55,"likelihood":1.1,"exploitation":25,"ransomware":0},"changes":[]}