Critical Authentication Bypass in SimpleHelp_OIDC Exposes Enterprise Accounts to Zero-Interaction Takeovers
Overview
CVE-2026-48558 presents an immediate risk to organizations using SimpleHelp with OpenID Connect (OIDC) authentication. This critical vulnerability (CVSS 10.0) allows unauthenticated attackers to forge identity tokens with arbitrary claims, bypassing authentication and multi-factor controls without user interaction.
Technical Analysis
The vulnerability stems from simplehelp's failure to verify cryptographic signatures on OIDC identity tokens during login. Attackers can craft unsigned tokens with elevated privilege claims, which the system accepts as valid credentials. Exploitation requires no user interaction and executes entirely at the authentication layer, making detection challenging. Enterprise environments deploying pre-release versions of simplehelp 6.0 or versions up to 5.5.15 are vulnerable.
Enterprise & DIB Impact
For Defense Industrial Base (DIB) and enterprise operations, this flaw could enable malicious actors to establish fully privileged technician sessions, compromising sensitive systems. Given the criticality of IT support platforms in enterprise environments, exploitation could lead to operational disruption, data exfiltration, or lateral movement within infrastructure.
Recommended Actions
- Upgrade to simplehelp version 5.5.16 or 6.0 final release
- disable OIDC authentication if unused
- monitor authentication endpoints for anomalous login patterns
- segment network access to support systems
- and conduct emergency security reviews of third-party authentication implementations
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →