ID:13034 - Exploit for Improper authentication in SimpleHelp - CVE-2026-48558

 
Main Vulnerability Database Exploits ID:13034 - Exploit for Improper authentication in SimpleHelp - CVE-2026-48558

ID:13034 - Exploit for Improper authentication in SimpleHelp - CVE-2026-48558

Published: September 2, 2026


Vulnerability identifier: #VU135974
Vulnerability risk: Critical
CVE-ID: CVE-2026-48558
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
SimpleHelp

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass authentication and create a new technician account.

The vulnerability exists due to improper authentication in OIDC assertion validation when processing OIDC-based logins. A remote attacker can submit forged identity provider assertions to create and authenticate as a new technician user to bypass authentication and create a new technician account.

The issue affects deployments with at least one configured OIDC authentication provider, an associated TechnicianGroup, and the "Allow group authenticated logins" setting enabled. Even when MFA is enforced for technicians, first-login self-registration of MFA can allow that protection to be bypassed.

Note, the vulnerability is being actively exploited in the wild. 


Remediation

Install security update from vendor's website.