---
id: CVE-2026-48558
title: >-
  SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an
  authentication bypass vulnerability in the OIDC authentication flow
summary: >-
  SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an
  authentication bypass vulnerability in the OIDC authentication flow. When OIDC
  authentication is configured, identity tokens submitted during login are
  accepted…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-347
vendor: simple-help
product: simplehelp
affected:
  - simplehelp < 5.5.16
  - simplehelp = 6.0
patched:
  - simplehelp 5.5.16
published: '2026-06-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:17:12.940'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48558'
references:
  - url: >-
      https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
    label: disclosure@vulncheck.com
  - url: 'https://simple-help.com/release-news'
    label: disclosure@vulncheck.com
  - url: 'https://simple-help.com/security/simplehelp-security-update-2026-05'
    label: disclosure@vulncheck.com
  - url: >-
      https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48558
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-06-30T03:55:22.397894Z'
epss: 0.05719
epssPercentile: 0.9282
kev: true
kevDateAdded: '2026-06-29'
kevDueDate: '2026-07-02'
kevRansomware: false
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/J4ck3LSyN-Gen2/CVE-2026-48558'
  metasploit:
    - exploit/multi/http/simplehelp_oidc_auth_bypass_rce
  nuclei:
    - CVE-2026-48558
  checkedAt: '2026-10-07T20:47:22.833Z'
ingestedAt: '2026-10-07T20:46:46.955Z'
---

## Overview

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

## Affected

- `simplehelp < 5.5.16`
- `simplehelp = 6.0`

## Remediation

Upgrade past the affected range:

- `simplehelp 5.5.16`
