news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-48558

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
10.0 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Risk score
100.0
Known exploited
CISA KEV
Published
2026-06-12
Status
Analyzed

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

Weaknesses

CWE-347

Coverage 6

threat-intel

Catan and Mouse

This Cisco Talos Threat Source newsletter highlights the emergence of ARToken, a sophisticated phishing-as-a-service (PhaaS) platform with capabilities previously undocumented. The platform, similar to EvilTokens, offers…

Cisco Talos · Jul 2, 2026 High

Advisories and references