logo

SimpleHelp Authentication Bypass Exploited to Hijack Remote Endpoints

ID: 7389ce9f-9844-5b21-861f-6554c1fb7fbd

STIX ID: report--7389ce9f-9844-5b21-861f-6554c1fb7fbd

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-13

Date Updated: 2026-06-13

Author: Do Son

...
...

Critical vulnerability CVE-2026-48558 in SimpleHelp allows unauthenticated attackers to forge OIDC identity tokens (due to missing signature verification) to obtain full technician/admin sessions and bypass MFA; threat intelligence reports ~14,000 internet-facing instances with ~7.2% in a vulnerable configuration, and recommended mitigations include immediate patching, restricting authentication IPs, and hardening the OIDC flow.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.