CVE-2026-48558 is a critical (CVSS 10.0) OIDC authentication bypass in SimpleHelp. Actively exploited; immediate update to version 5.5.16 is required.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| simplehelp | * | 5.5.16 | vulnerable |
| simplehelp | 6.0 | 6.0 | vulnerable |
Immediately update SimpleHelp to version 5.5.16 or later, which addresses the OIDC signature verification failure and mitigates the authentication bypass.
Identify and upgrade all SimpleHelp instances running versions 5.5.15 and prior, as well as any 6.0 pre-release versions, to the latest stable release.
Until patches are applied, disable OIDC authentication or restrict network access to the SimpleHelp technician interface to trusted IP addresses via a firewall or VPN.
Review technician session logs for unauthorized logins or sessions originating from unexpected geographic locations or IP addresses that do not align with known staff activity.
"Detect exploitation by auditing SimpleHelp logs for successful technician logins that do not have corresponding authentication records in your OIDC provider's logs. Monitor for unusual 'Technician Session Started' events, especially those bypassing MFA. Use network security tools to flag suspicious traffic to OIDC endpoints. Follow CISA's 'Forensics Triage Requirements' to check for indicators of compromise associated with forged identity claims in the OIDC flow."
Experience superior visibility and a simpler approach to cyber risk management