---
cve: "CVE-2026-48558"
severity: "CRITICAL"
cvss: 9.5
epss: "11.5%"
vendor: "Simplehelp"
kev: true
exploited: true
published: "2026-06-12 18:16:35"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T12:14:04+02:00"
---

# CVE-2026-48558

> 9.5 CRITICAL · ⚠️ CISA KEV (73 Tage) · 🔓 Exploited

## Beschreibung

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/>
- <https://simple-help.com/security/simplehelp-security-update-2026-05>
- <https://simple-help.com/release-news>
- <https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48558>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-48558) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
