Skip to main content

CVE detail

CVE-2026-48558

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

CVSS 9.5 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
20 evidence mentions in the snapshot
Diversity score
20.0
12 sources across 7 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
11
within the 30d window
Peak daily
5
highest bucket

Evidence

Source links by recency

Newest mentions first
20 source links · newest first
  • ity matters. They’ve built their reputation on finding the ones that do. This year, their AI-assisted research surfaced CVE-2026-34197, a remote code execution vulnerability in a widely deployed open-source message broker, and CVE-2026-48558, a critical authentication bypass in a remote monitoring and management platform. Both landed on CISA’s KEV Cata

    exploithorizon3.aiJul 15, 2026, 12:15 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is coming due Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated high risk far more often than anything else, and they get fixed slower than anything else. The figures come … More →

    newswww.helpnetsecurity.comJul 5, 2026, 5:10 AM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $1M to Data Extortion Group Kairos FBI: TeamPCP Compromised Dev Tools to […]

    newssecurityaffairs.comJul 5, 2026, 5:07 AM
  • Catan and MouseCisco Talos

    ty in the SimpleHelp remote monitoring and management (RMM) software has been exploited for malware delivery Tracked as CVE-2026-48558, the bug impacts SimpleHelp’s OpenID Connect authentication flow and allows a remote attacker to obtain a fully authenticated technician session. ( Security Week ) Can’t get enough Talos? Martin Lee: Running through the

    vendorblog.talosintelligence.comJul 2, 2026, 6:00 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a SimpleHelp flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SimpleHelp flaw, tracked as CVE-2026-48558 (CVSS score v3.1 of 10.0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-48558 is a critical authentication bypass vulnerability in SimpleHelp versions 5.5.15 and earlier and […]

    newssecurityaffairs.comJun 30, 2026, 7:47 PM
  • managed network. New analysis from security firm Blackpoint Cyber found that an attacker exploited the flaw, tracked as CVE-2026-48558, to obtain a trusted technician session on an internet-facing SimpleHelp server. The attacker then used the platform's own tools to push malware its researchers named TaskWeaver and Djinn Stealer. From Forged Token to F

    newswww.infosecurity-magazine.comJun 30, 2026, 3:34 PM
  • er two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (OIDC) flow that an unauthenticated

    newsthehackernews.comJun 30, 2026, 11:18 AM
  • Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets,” BlackPoint Cyber’s researchers discovered. CVE-2026-48558 exploited SimpleHelp is a remote monitoring and management (RMM) tool popular with managed services providers … More →

    newswww.helpnetsecurity.comJun 30, 2026, 10:25 AM
  • The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling.

    newswww.securityweek.comJun 30, 2026, 8:43 AM
  • The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.

    newswww.darkreading.comJun 29, 2026, 9:29 PM
  • one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48558 SimpleHelp Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD)

    governmentwww.cisa.govJun 29, 2026, 12:00 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring … More →

    newswww.helpnetsecurity.comJun 21, 2026, 8:00 AM
  • A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, and more. Maliciously “forged” Technician account (Source: Horizon3.ai) The vulnerability CVE-2026-48558 is an authentication bypass flaw affecting SimpleHelp deployments configured to use OpenID Connect (OIDC) authentication. “Even when the SimpleHelp server is configured to enforce MFA for technicians, … More →

    newswww.helpnetsecurity.comJun 16, 2026, 1:33 PM
  • CVE-2026-48558Horizon3.ai

    CVE-2026-48558 is an authentication bypass vulnerability affecting SimpleHelp OIDC deployments. The flaw may allow attackers to create unauthorized Technician accounts and gain privileged access to managed endpoints.

    exploithorizon3.aiJun 15, 2026, 4:05 PM
  • CVE-2026-35273Horizon3.ai

    CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability affecting Oracle PeopleSoft PeopleTools. Threat intelligence confirms active exploitation by ShinyHunters prior to disclosure.

    exploithorizon3.aiJun 12, 2026, 8:04 PM
  • No excerpt available.

    Mitigationwww.cisa.govJun 12, 2026, 6:16 PM
  • No excerpt available.

    Third Party Advisoryblackpointcyber.comJun 12, 2026, 6:16 PM
  • No excerpt available.

    Vendor Advisorysimple-help.comJun 12, 2026, 6:16 PM
  • https://simple-help.com/release-newssimple-help.com

    No excerpt available.

    Vendor Advisorysimple-help.comJun 12, 2026, 6:16 PM
  • Horizon3.ai details indicators of compromise, affected configurations, and mitigation guidance for CVE-2026-48558, a SimpleHelp OIDC authentication bypass vulnerability.

    exploithorizon3.aiJun 12, 2026, 3:38 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-14837

    Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification o…

    CVSS 8.5 · High
    1 mention
  • CVE-2026-48021

    In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controll…

    CVSS 9.1 · Critical
    3 mentions
  • CVE-2026-52686

    The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME…

    CVSS 3.7 · Low
    1 mention
  • CVE-2026-13089

    OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin an alg…

    CVSS N/A · Unrated
    4 mentions
  • CVE-2026-10723

    BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 thr…

    CVSS 6.8 · Medium
    3 mentions
  • CVE-2026-64623

    Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as val…

    CVSS 8.8 · High
    2 mentions