CVE-2026-48558
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.5EPSS 0.7%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Lifecycle
12 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
SimpleHelp · SimpleHelppublic PoCs found — 1
cve_referencehorizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →