Knox CVE Database
/
CVE-2026-48558
Critical
9.5

CVE-2026-48558: SimpleHelp Authentication Bypass Vulnerability

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

Added to the CISA KEV catalog:
June 29, 2026

Overview

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

Vulnerability details

Affected vendor
SimpleHelp
Affected product
SimpleHelp
Weakness type (CWE)
CWE-347

This vulnerability is a CWE-347 (Improper Verification of Cryptographic Signature) flaw in SimpleHelp's OIDC authentication handler. OIDC relies on identity tokens (JWTs) that are cryptographically signed by the identity provider so a relying party can trust the claims inside them, such as user identity and group membership. When the relying party fails to validate that signature, it has no way to distinguish a token genuinely issued by the configured identity provider from one fabricated by any third party, collapsing the trust boundary the protocol is designed to enforce.

Because signature verification is skipped, an attacker does not need valid credentials, an account, or interaction with the real identity provider — they can construct a JWT by hand containing whatever subject, role, or group claims are needed to be recognized as a privileged technician. Given the CVSS 4.0 vector (AV:N, AC:L, PR:N, UI:N), this is exploitable remotely over the network with low complexity and no privileges or user interaction, and it yields high impact to confidentiality, integrity, and availability — consistent with obtaining a fully authenticated technician session capable of remote access to managed endpoints, and in some configurations bypassing MFA entirely.

Severity and impact

9.5
Critical
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
X
Confidentiality impact
Integrity impact
Availability impact

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review SimpleHelp authentication/session logs for technician logins via OIDC where the identity token issuer or claims are inconsistent with your actual IdP's known user population.
  • Alert on new technician sessions established without a corresponding successful authentication event in the upstream identity provider's own logs.
  • Monitor for unexpected or anomalous JWT structures in authentication traffic to the SimpleHelp server, such as tokens with missing, malformed, or 'none'-type signature algorithms.
  • Flag technician sessions that immediately initiate remote control, file transfer, or command execution against endpoints shortly after login, especially from unfamiliar source IPs.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 2, 2026

Additional hardening

  • If OIDC authentication is enabled but not strictly required for operations, temporarily disable it and fall back to local or another verified authentication method until remediated.
  • Restrict network access to the SimpleHelp server's authentication endpoints to trusted management networks or VPN, reducing exposure to unauthenticated remote attackers.
  • Enforce strict validation at any reverse proxy or WAF in front of SimpleHelp by rejecting malformed or unsigned JWTs before they reach the application.
  • Audit existing technician accounts and active sessions for unrecognized identities, and rotate session tokens or force re-authentication after applying compensating controls.

Key dates

Published (NVD)
June 12, 2026
Added to CISA KEV
June 29, 2026
Remediation deadline
July 2, 2026
Last updated
June 30, 2026

References

Frequently asked questions

Does CVE-2026-48558 affect my FedRAMP authorization?

If SimpleHelp SimpleHelp runs inside your authorization boundary, yes. CVE-2026-48558 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of July 2, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-48558?

Knox doesn't patch your software for you — remediating SimpleHelp SimpleHelp is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-48558 isn't remediated by July 2, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting