← Back to Vulnerability Reports CVE Intelligence

CVE-2026-48558

SimpleHelp In the wild In CISA KEV

What is CVE-2026-48558?

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

CVSSawaiting NVD
Exploitation In the wild In CISA KEV
EPSS1% · P49
Triage statusActive Exploit
ActionPatch immediately

Timeline

  • 2026-06-29Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2026-06-30First covered in a defend.network daily briefing
  • 2026-07-02CISA federal remediation deadline (BOD 22-01)

CISA Known Exploited Vulnerability

SimpleHelp Authentication Bypass Vulnerability

Added to KEV2026-06-29
Federal patch deadline2026-07-02
Known ransomware useUnknown

Affected product

SimpleHelp

Remediation Steps

  1. Apply the vendor patch for SimpleHelp as issued by the vendor
  2. Review access logs for evidence of exploitation or credential theft
  3. Rotate credentials for cloud, development, and administrative accounts
  4. Monitor systems for installation or execution of Djinn Stealer or similar info-stealers
  5. Restrict network access to SimpleHelp instances to trusted administrative networks only

Browse all tracked CVEs in the defend.network CVE database →

🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.