Critical severity10.0CISA KEVNVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026
CVE-2026-48558
CVE-2026-48558
Description
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=5.5.15
Patches
Vulnerability mechanics
References
3News mentions
16- Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHelp Net Security · Jul 5, 2026
- Catan and MouseCisco Talos Intelligence · Jul 2, 2026
- CISA Warns of SimpleHelp Authentication Bypass Vulnerability Exploited in AttacksCyber Security News · Jul 2, 2026
- Critical SimpleHelp Vulnerability Exploited For Malware DeliveryInfosecurity Magazine · Jun 30, 2026
- Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn StealerThe Hacker News · Jun 30, 2026
- SimpleHelp Authentication Bypass Vulnerability Exploited in the Wild to Deploy TaskWeaver LoaderCyber Security News · Jun 30, 2026
- SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Help Net Security · Jun 30, 2026
- Critical SimpleHelp Vulnerability Exploited for Malware DeliverySecurityWeek · Jun 30, 2026
- 'Djinn' Stealer Targets Cloud, AI CredentialsDark Reading · Jun 29, 2026
- Critical SimpleHelp flaw exploited to deploy new stealer malwareBleepingComputer · Jun 29, 2026
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026
- Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security · Jun 21, 2026
- SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558)Help Net Security · Jun 16, 2026
- Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass DisclosureCyber Security News · Jun 16, 2026
- SimpleHelp bug lets hackers create rogue remote support accountsBleepingComputer · Jun 15, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts