Improper authentication in SimpleHelp - CVE-2026-48558
Published: June 30, 2026
SimpleHelp
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication and create a new technician account.
The vulnerability exists due to improper authentication in OIDC assertion validation when processing OIDC-based logins. A remote attacker can submit forged identity provider assertions to create and authenticate as a new technician user to bypass authentication and create a new technician account.
The issue affects deployments with at least one configured OIDC authentication provider, an associated TechnicianGroup, and the "Allow group authenticated logins" setting enabled. Even when MFA is enforced for technicians, first-login self-registration of MFA can allow that protection to be bypassed.
Note, the vulnerability is being actively exploited in the wild.
How to mitigate CVE-2026-48558
Sources
- https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.23
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.119
- https://simple-help.com/security/simplehelp-security-update-2026-05