Vulnerability  ·  2026-06-30

SimpleHelp — OIDC Authentication Bypass Allows Unauthenticated Account Takeover (CISA KEV)

VulnerabilityHigh impactGlobalCVE-2026-48558
SimpleHelp contains an authentication bypass vulnerability in its OIDC authentication flow (CWE-347: Improper Verification of Cryptographic Signature). When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. A remote unauthenticated attacker can forge or replay an OIDC token for any user account — including administrators — gaining full access without valid credentials. CISA added this to the KEV catalog on 2026-06-29 with a federal agency remediation deadline of 2026-07-02.
SimpleHelp is an RMM (remote monitoring and management) platform used by 6,000+ companies in 70+ countries. RMM tools are high-value targets for ransomware actors and APTs because they provide persistent privileged access to managed endpoints at scale. While not AI-native, SimpleHelp is increasingly integrated into agentic IT automation workflows and AI-driven SOC tooling as a remote-execution backend. An auth bypass gives attackers the same agent-level access to all managed endpoints.
Remote unauthenticated attacker submits a crafted or replayed OIDC identity token to the SimpleHelp login endpoint; the server accepts it without signature verification, granting full administrative access.
SimpleHelp (versions addressed in 2026-05 security update)
Apply SimpleHelp 2026-05 security update immediately. Federal agencies must remediate by 2026-07-02 per CISA BOD 26-04. Advisory: https://simple-help.com/security/simplehelp-security-update-2026-05
Sources
SimpleHelp Security Update 2026-05CISA KEV CatalogNVD CVE-2026-48558
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →