No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Fri, 12 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simple-help
Simple-help simplehelp |
|
| Vendors & Products |
Simple-help
Simple-help simplehelp |
Fri, 12 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required. | |
| Title | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-12T18:47:10.290Z
Reserved: 2026-05-21T18:34:46.418Z
Link: CVE-2026-48558
Updated: 2026-06-12T18:21:36.880Z
Status : Received
Published: 2026-06-12T18:16:35.317
Modified: 2026-06-12T18:16:35.317
Link: CVE-2026-48558
No data.
OpenCVE Enrichment
Updated: 2026-06-12T19:45:27Z