SimpleHelp Authentication Bypass Exploited to Hijack Remote Endpoints
ID: 7389ce9f-9844-5b21-861f-6554c1fb7fbd
STIX ID: report--7389ce9f-9844-5b21-861f-6554c1fb7fbd
Feed Name: securityonline.info
Threat Score
Critical vulnerability CVE-2026-48558 in SimpleHelp allows unauthenticated attackers to forge OIDC identity tokens (due to missing signature verification) to obtain full technician/admin sessions and bypass MFA; threat intelligence reports ~14,000 internet-facing instances with ~7.2% in a vulnerable configuration, and recommended mitigations include immediate patching, restricting authentication IPs, and hardening the OIDC flow.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
