CVE-2026-48558
CRITICAL KEVSimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
Title source: cnaExploitation Summary
CVE-2026-48558 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 29, 2026. EIP tracks 1 public exploit from researchers including J4ck3LSyN-Gen2.
AI-analyzed exploit summary This PoC exploits CVE-2026-48558, an OIDC authentication bypass in SimpleHelp servers (versions ≤5.5.15 and 6.0 pre-releases) by forging unsigned JWT tokens to gain unauthorized Technician access. The exploit targets the OIDC callback endpoint to impersonate privileged users without signature verification.
Description
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
Exploits (1)
This PoC exploits CVE-2026-48558, an OIDC authentication bypass in SimpleHelp servers (versions ≤5.5.15 and 6.0 pre-releases) by forging unsigned JWT tokens to gain unauthorized Technician access. The exploit targets the OIDC callback endpoint to impersonate privileged users without signature verification.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H