What is CVE-2026-48558?
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
Timeline
- 2026-06-12Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-29Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-06-30First covered in a defend.network daily briefing
- 2026-06-30NVD record last updated
- 2026-07-02CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
SimpleHelp Authentication Bypass Vulnerability
Affected product
Simple-Help Simplehelp
Remediation Steps
- Apply the vendor security update for SimpleHelp as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References
- https://simple-help.com/security/simplehelp-security-update-2026-05
- https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
- https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
- https://simple-help.com/release-news
- https://nvd.nist.gov/vuln/detail/CVE-2026-48558
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of July 2026 (July 20 – 26)
- Vulnerability Priority Report – Week 2 of July 2026 (July 13 – 19)
- Vulnerability Priority Report – Week 1 of July 2026 (July 6 – 12)
- Vulnerability Priority Report – Week 5 of June 2026 (June 29 – July 5)
- AI agent poisoning, Langflow RCE exploited: Microsoft warns data theft risks (2026-07-01)
- Oracle PeopleSoft breaches widen; malicious Chrome extension steals searches; Mustang Panda targets India (2026-06-30)
Browse all tracked CVEs in the defend.network CVE database →