CVE-2026-48558: listed in the CISA KEV catalog

CVE-2026-48558 · CVSS 10.0 CRITICAL · EPSS 11% · KEV 2026-06-29

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

Is CVE-2026-48558 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-48558

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.