Status: KEV
| Advisory ID: CVE-2026-48558
Key Details
| CVE | CVE-2026-48558 |
| Vulnerability Name | SimpleHelp Authentication Bypass Vulnerability |
| Affected products | SimpleHelp SimpleHelp |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-347 (Improper Verification of Cryptographic Signature) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-06-29. |
| Exploitation prediction (EPSS) | 5.72% probability of exploitation in the next 30 days (93% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-07-02 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
What to Do
Monitor SimpleHelp 's web page for any future patch releases.
References
KEV Required Action