Knox CVE Database
/
CVE-2026-48558
Critical
9.5

CVE-2026-48558: SimpleHelp Authentication Bypass Vulnerability

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

Added to the CISA KEV catalog:
June 29, 2026

Overview

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

Vulnerability details

Affected vendor
SimpleHelp
Affected product
SimpleHelp
Weakness type (CWE)
CWE-347

SimpleHelp's OIDC authentication flow fails to verify the cryptographic signature of identity tokens submitted during login (CWE-347). In a correctly implemented OIDC flow, the relying party must validate the IdP-issued token signature before trusting any identity claims it contains. SimpleHelp skips this check, meaning the server accepts tokens as authoritative regardless of whether they were issued by a legitimate identity provider. The flaw affects servers configured with either generic OIDC or Azure AD OIDC authentication, and is present in versions 5.5.15 and earlier and 6.0 pre-releases prior to RC2.


An unauthenticated remote attacker submits a forged identity token containing attacker-chosen claims, such as an email address and group membership, to the SimpleHelp login endpoint. Three conditions must be present: OIDC is configured, at least one TechnicianGroup is associated with the OIDC provider, and 'Allow group authenticated logins' is enabled on that group. When these conditions are met, the server creates and authenticates a fully privileged Technician session. MFA is also bypassed because first-time technician logins permit self-registration of MFA methods. Active exploitation has been observed, with attackers subsequently deploying malware across managed endpoints using the RMM platform's native file transfer and remote execution capabilities.

Severity and impact

9.5
Critical
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review the SimpleHelp admin console at Administration -> Technicians -> Gear Icon -> 'Show Group Authenticated Users' for unfamiliar technician names or email addresses not associated with known staff or your configured identity provider.
  • Inspect server logs at /opt/SimpleHelp/logs/server.log or /opt/SimpleHelp/logs/<YYYYMMDD-HHMMSS>/server.log for 'Registering technician login' or 'Configuration save requested' entries referencing unrecognized email addresses, particularly addresses not matching your organization's domain.
  • Audit managed endpoints for unexpected file transfers or script executions originating from the SimpleHelp server, especially delivery of JavaScript files (such as files named jquery.js) executed through node.exe, which has been observed in confirmed post-exploitation activity.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 2, 2026

Additional hardening

  • Apply IP restrictions on technician authentication immediately via Administration -> Login Security to limit OIDC login attempts to known corporate IP ranges, reducing exposure while patching is scheduled.
  • Disable 'Allow group authenticated logins' on all TechnicianGroups if OIDC authentication is not operationally required, removing the specific configuration condition the vulnerability requires.
  • Restrict internet exposure of the SimpleHelp management interface at the network perimeter; the server should not accept unauthenticated inbound connections from arbitrary internet sources.
  • Audit all existing Technician accounts and revoke any sessions or accounts created after the earliest possible exposure window, treating any credentials accessible from managed endpoints as potentially compromised.

Key dates

Published (NVD)
June 12, 2026
Added to CISA KEV
June 29, 2026
Remediation deadline
July 2, 2026
Last updated
June 30, 2026

References

Frequently asked questions

Does CVE-2026-48558 affect my FedRAMP authorization?

If SimpleHelp runs inside your authorization boundary, CVE-2026-48558 is a direct concern. CISA's Known Exploited Vulnerabilities catalog lists this vulnerability with a remediation deadline of July 2, 2026. For a FedRAMP-authorized service, an unpatched Known Exploited Vulnerability inside your boundary is an assessor finding — one you must either remediate or formally document a mitigation for before your assessor or sponsoring agency raises it first.

How does Knox help me handle CVE-2026-48558?

Remediating SimpleHelp is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The remediation work is yours to execute; maintaining a defensible compliance posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis, including exposures like CVE-2026-48558. That means gaps surface during ongoing monitoring rather than only when an assessor flags them at review time, giving you the lead time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Book a meeting with Knox to map your path to authorization. The offer is direct: FedRAMP in 90 days for 90% less, without the delays or dependencies of traditional authorization approaches.

What happens if CVE-2026-48558 isn't remediated by July 2, 2026?

If CVE-2026-48558 is unresolved past July 2, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship on solid footing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting