CVE-2026-48558
Published Jun 12, 2026
Last updated a month ago
AI description
CVE-2026-48558 is an authentication bypass vulnerability found in SimpleHelp, a remote support and remote monitoring and management (RMM) platform. The flaw specifically affects the OpenID Connect (OIDC) authentication flow in SimpleHelp versions 5.5.15 and prior, as well as 6.0 pre-release builds. The vulnerability stems from SimpleHelp's improper verification of cryptographic signatures on OIDC identity tokens during the login process. This oversight allows an unauthenticated attacker to forge an OIDC identity token containing arbitrary identity claims. By submitting this crafted token, the attacker can obtain a fully authenticated technician session, potentially bypassing multi-factor authentication in some configurations. Real-world exploitation of CVE-2026-48558 has been observed, with attackers leveraging it to deploy infostealer payloads, including the previously undocumented Djinn Stealer and TaskWeaver malware.
- Description
- SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
- Products
- simplehelp
CVSS 4.0
- Type
- Secondary
- Base score
- 9.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- SimpleHelp Authentication Bypass Vulnerability
- Exploit added on
- Jun 29, 2026
- Exploit action due
- Jul 2, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- disclosure@vulncheck.com
- CWE-347
- Hype score
- Not currently trending
CVE-2026-48558. 0day Intel: Publication of an exploit (PoC) for SimpleHelp (CVE-2026-48558) PT ID: PT-2026-4
@lyrie_ai
20 Jul 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
23 vulnerabilities were added to the CISA KEV list this past month, with an aggressive focus on authentication bypasses and RCE bugs targeting core network-edge and monitoring infrastructure. Key Exploitation Vectors to Patch Immediately were: SimpleHelp RMM (CVE-2026-48558 - h
@hackerstorm
9 Jul 2026
160 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
【サイバーセキュリティ動向分析】 今日のサイバーセキュリティニュース(2026年7月5日時点)の主なトピックを、背景・影響・対策を含めて長文でまとめます。 1. SimpleHelp RMMツールの深刻な認証バイパス脆
@kenebeii
5 Jul 2026
1528 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Recent exploits: CVE-2026-8451 (Citrix NetScaler) allows memory disclosure. CVE-2026-48558 (SimpleHelp) is a critical auth bypass used for info stealer deployment. Both severely compromise data privacy & integrity in transit. #Cybersecurity #News #Vulnerabilities
@YourAnon_irc
5 Jul 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-48558 (CVSS 10.0): Kritische Auth-Bypass in SimpleHelp RMM wird aktiv ausgenutzt. Angreifer erhalten vollständigen Technician-Zugriff und liefern Malware. Patchen Sie sofort. #CyberSecurity #CVE #RMM https://t.co/MoAI77aqiV
@wall_your_x
3 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Publication of an exploit (PoC) for SimpleHelp (CVE-2026-48558) PT ID: PT-2026-48947 For informational purposes only. Type of vulnerability: Authentication Bypass Affected versions: SimpleHelp 5.5.15 and lower, 6.0 RC1 and lower (with OIDC authentication enabled) Privileges ht
@ptdbugs
1 Jul 2026
1625 Impressions
1 Retweet
14 Likes
5 Bookmarks
0 Replies
0 Quotes
It's Already When. — Field Note Active exploitation hits SimpleHelp (CVE-2026-48558) and Oracle EBS (CVE-2026-46817), while a public PoC drops for the libssh2 client fla... https://t.co/IaHFrXvk3x #CyberSecurity #ThreatIntel
@itsalreadywhen
30 Jun 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sale of an exploit for a 1-day vulnerability in SimpleHelp (CVE-2026-48558) PT ID: PT-2026-48947 For informational purposes only. Type of vulnerability: Authentication Bypass via OIDC, with escalation to command execution on managed endpoints Affected versions: SimpleHelp https
@ptdbugs
18 Jun 2026
248 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558): A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated… https://t.co/gCiDW0gvyG http
@shah_sheikh
16 Jun 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 GÜVENLİK BÜLTENİ: SimpleHelp'te Kritik Kimlik Doğrulama Atlatma Zafiyeti (CVE-2026-48558) Merhaba #Brolyz Uzaktan destek ve yönetim araçlarını yakından ilgilendiren oldukça kritik bir gelişme yaşandı.SimpleHelp yazılımında tespit edilen ve CVSS puanı 10.0
@rahmid3mir
14 Jun 2026
57 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-48558 — CVSS 10/10 ██████████ SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Mqfh6nyKqn
@OrizonCyber
12 Jun 2026
85 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:*",
"matchCriteriaId": "60E78059-D944-49AD-B48D-0CFA8BE13598",
"versionEndExcluding": "5.5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:simple-help:simplehelp:6.0:pre-release:*:*:*:*:*:*",
"matchCriteriaId": "4647570F-9368-4088-9E52-F63091C74B68",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]