oM noM Security Feeds cve
vulnerability context

CVE-2026-48558

CVSS 10.0 CRITICALEPSS 49%CWE-347OTX 10 pulses

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

Published 2026-06-12 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
10.0 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
49% percentile (score 0.0072)
CWE
CWE-347
OTX pulses
10 total, 0 recent

source mentions 2

source consensus

  • Bluesky
  • BleepingComputer
Want the 3-bullet summary of CVE-2026-48558, plus webhook alerts when KEV is updated? Pro is $10/mo.