CVE-2026-48558: listed in the CISA KEV catalog CVE-2026-48558 · CVSS 10.0 CRITICAL · EPSS 6% · KEV 2026-06-29
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
Is CVE-2026-48558 exploited? Listed in the CISA KEV catalog on 2026-06-29. Federal remediation due 2026-07-02. Past that date by 90 days. EPSS puts exploitation in the next 30 days at 6%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2026-48558 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-09-24.
CVE-2026-48558: listed in the CISA KEV catalog CVE-2026-48558 · CVSS 10.0 CRITICAL · EPSS 6% · KEV 2026-06-29
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
Is CVE-2026-48558 exploited? Listed in the CISA KEV catalog on 2026-06-29. Federal remediation due 2026-07-02. Past that date by 90 days. EPSS puts exploitation in the next 30 days at 6%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2026-48558 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-09-24.