Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-48558

Published 2026-06-12
Updated 3 months ago
Vendor/s
SimpleHelp
Product/s
SimpleHelp
Version/s
* > 5.5.16
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
10
/ 10
Critical
Severity Details
Base score
10 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-48558 is a critical (CVSS 10.0) OIDC authentication bypass in SimpleHelp. Actively exploited; immediate update to version 5.5.16 is required.

CPE

SimpleHelp  logo
SimpleHelp
Product Version Start Version End (excl.) Status
simplehelp * 5.5.16 vulnerable
simplehelp 6.0 6.0 vulnerable

Related weakness (CWE)

CWE-347

Remediation plan

1

Apply official patches

Immediately update SimpleHelp to version 5.5.16 or later, which addresses the OIDC signature verification failure and mitigates the authentication bypass.

2

Update affected systems

Identify and upgrade all SimpleHelp instances running versions 5.5.15 and prior, as well as any 6.0 pre-release versions, to the latest stable release.

3

Restrict access

Until patches are applied, disable OIDC authentication or restrict network access to the SimpleHelp technician interface to trusted IP addresses via a firewall or VPN.

4

Monitor for exploitation

Review technician session logs for unauthorized logins or sessions originating from unexpected geographic locations or IP addresses that do not align with known staff activity.

Detection Guidance

"Detect exploitation by auditing SimpleHelp logs for successful technician logins that do not have corresponding authentication records in your OIDC provider's logs. Monitor for unusual 'Technician Session Started' events, especially those bypassing MFA. Use network security tools to flag suspicious traffic to OIDC endpoints. Follow CISA's 'Forensics Triage Requirements' to check for indicators of compromise associated with forged identity claims in the OIDC flow."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management