CVE-2026-48558

Published Jun 12, 2026

Last updated a month ago

Exploit knownCVSS critical 9.5
npm
Network
Container Security
ICS
Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-48558 is an authentication bypass vulnerability found in SimpleHelp, a remote support and remote monitoring and management (RMM) platform. The flaw specifically affects the OpenID Connect (OIDC) authentication flow in SimpleHelp versions 5.5.15 and prior, as well as 6.0 pre-release builds. The vulnerability stems from SimpleHelp's improper verification of cryptographic signatures on OIDC identity tokens during the login process. This oversight allows an unauthenticated attacker to forge an OIDC identity token containing arbitrary identity claims. By submitting this crafted token, the attacker can obtain a fully authenticated technician session, potentially bypassing multi-factor authentication in some configurations. Real-world exploitation of CVE-2026-48558 has been observed, with attackers leveraging it to deploy infostealer payloads, including the previously undocumented Djinn Stealer and TaskWeaver malware.

Description
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
Source
disclosure@vulncheck.com
NVD status
Analyzed
Products
simplehelp

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
SimpleHelp Authentication Bypass Vulnerability
Exploit added on
Jun 29, 2026
Exploit action due
Jul 2, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

disclosure@vulncheck.com
CWE-347

Social media

Hype score
Not currently trending
  1. CVE-2026-48558. 0day Intel: Publication of an exploit (PoC) for SimpleHelp (CVE-2026-48558) PT ID: PT-2026-4

    @lyrie_ai

    20 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 23 vulnerabilities were added to the CISA KEV list this past month, with an aggressive focus on authentication bypasses and RCE bugs targeting core network-edge and monitoring infrastructure. Key Exploitation Vectors to Patch Immediately were: SimpleHelp RMM (CVE-2026-48558 - h

    @hackerstorm

    9 Jul 2026

    160 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 【サイバーセキュリティ動向分析】 今日のサイバーセキュリティニュース(2026年7月5日時点)の主なトピックを、背景・影響・対策を含めて長文でまとめます。 1. SimpleHelp RMMツールの深刻な認証バイパス脆

    @kenebeii

    5 Jul 2026

    1528 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Recent exploits: CVE-2026-8451 (Citrix NetScaler) allows memory disclosure. CVE-2026-48558 (SimpleHelp) is a critical auth bypass used for info stealer deployment. Both severely compromise data privacy & integrity in transit. #Cybersecurity #News #Vulnerabilities

    @YourAnon_irc

    5 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-48558 (CVSS 10.0): Kritische Auth-Bypass in SimpleHelp RMM wird aktiv ausgenutzt. Angreifer erhalten vollständigen Technician-Zugriff und liefern Malware. Patchen Sie sofort. #CyberSecurity #CVE #RMM https://t.co/MoAI77aqiV

    @wall_your_x

    3 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Publication of an exploit (PoC) for SimpleHelp (CVE-2026-48558) PT ID: PT-2026-48947 For informational purposes only. Type of vulnerability: Authentication Bypass Affected versions: SimpleHelp 5.5.15 and lower, 6.0 RC1 and lower (with OIDC authentication enabled) Privileges ht

    @ptdbugs

    1 Jul 2026

    1625 Impressions

    1 Retweet

    14 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  7. It's Already When. — Field Note Active exploitation hits SimpleHelp (CVE-2026-48558) and Oracle EBS (CVE-2026-46817), while a public PoC drops for the libssh2 client fla... https://t.co/IaHFrXvk3x #CyberSecurity #ThreatIntel

    @itsalreadywhen

    30 Jun 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Sale of an exploit for a 1-day vulnerability in SimpleHelp (CVE-2026-48558) PT ID: PT-2026-48947 For informational purposes only. Type of vulnerability: Authentication Bypass via OIDC, with escalation to command execution on managed endpoints Affected versions: SimpleHelp https

    @ptdbugs

    18 Jun 2026

    248 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  9. SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558): A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated… https://t.co/gCiDW0gvyG http

    @shah_sheikh

    16 Jun 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 GÜVENLİK BÜLTENİ: SimpleHelp'te Kritik Kimlik Doğrulama Atlatma Zafiyeti (CVE-2026-48558) Merhaba #Brolyz Uzaktan destek ve yönetim araçlarını yakından ilgilendiren oldukça kritik bir gelişme yaşandı.SimpleHelp yazılımında tespit edilen ve CVSS puanı 10.0

    @rahmid3mir

    14 Jun 2026

    57 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 CVE-2026-48558 — CVSS 10/10 ██████████ SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Mqfh6nyKqn

    @OrizonCyber

    12 Jun 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations