SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
SimpleHelp's OIDC authentication flow fails to verify the cryptographic signature of identity tokens submitted during login (CWE-347). In a correctly implemented OIDC flow, the relying party must validate the IdP-issued token signature before trusting any identity claims it contains. SimpleHelp skips this check, meaning the server accepts tokens as authoritative regardless of whether they were issued by a legitimate identity provider. The flaw affects servers configured with either generic OIDC or Azure AD OIDC authentication, and is present in versions 5.5.15 and earlier and 6.0 pre-releases prior to RC2.
An unauthenticated remote attacker submits a forged identity token containing attacker-chosen claims, such as an email address and group membership, to the SimpleHelp login endpoint. Three conditions must be present: OIDC is configured, at least one TechnicianGroup is associated with the OIDC provider, and 'Allow group authenticated logins' is enabled on that group. When these conditions are met, the server creates and authenticates a fully privileged Technician session. MFA is also bypassed because first-time technician logins permit self-registration of MFA methods. Active exploitation has been observed, with attackers subsequently deploying malware across managed endpoints using the RMM platform's native file transfer and remote execution capabilities.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If SimpleHelp runs inside your authorization boundary, CVE-2026-48558 is a direct concern. CISA's Known Exploited Vulnerabilities catalog lists this vulnerability with a remediation deadline of July 2, 2026. For a FedRAMP-authorized service, an unpatched Known Exploited Vulnerability inside your boundary is an assessor finding — one you must either remediate or formally document a mitigation for before your assessor or sponsoring agency raises it first.
Remediating SimpleHelp is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The remediation work is yours to execute; maintaining a defensible compliance posture while you do it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis, including exposures like CVE-2026-48558. That means gaps surface during ongoing monitoring rather than only when an assessor flags them at review time, giving you the lead time to act before a finding becomes a formal problem.
Book a meeting with Knox to map your path to authorization. The offer is direct: FedRAMP in 90 days for 90% less, without the delays or dependencies of traditional authorization approaches.
If CVE-2026-48558 is unresolved past July 2, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship on solid footing.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









