Junglewise Threat Intelligence

CVE-2026-48558: SimpleHelp authentication bypass in OIDC authentication flow

CVE-2026-48558 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-06-12

Technologies: SimpleHelp. Vendors: Simplehelp.

Executive brief

SimpleHelp, a remote support and management software, contains a critical security flaw in how it handles logins via OpenID Connect (OIDC). An attacker can bypass the login screen by providing a fake identity token that the system fails to verify, granting them full administrative access to the technician console. This allows unauthorized parties to control managed computers, access sensitive data, and potentially bypass multi-factor authentication.

Technical details

An authentication bypass vulnerability (CWE-347) exists in SimpleHelp versions 5.5.15 and prior, as well as 6.0 pre-release versions. The root cause is a failure to verify the cryptographic signatures of OIDC identity tokens during the authentication flow. A remote, unauthenticated attacker can exploit this by submitting a forged JWT containing arbitrary identity claims. Successful exploitation results in a fully authenticated technician session and can bypass multi-factor authentication (MFA) if OIDC is the primary auth mechanism. The vulnerability has been reported as exploited in the wild.

Affected products

  • SimpleHelp SimpleHelp 5.5.15 and prior, 6.0 pre-release versions prior to 6.0 RC2

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory
  • 2026-06-29: other: NVD publication date

Related threats