Impact
SimpleHelp versions 5.5.15 and earlier, as well as pre‑release 6.0 releases, allow an attacker to bypass authentication by submitting an OIDC identity token without the server verifying its cryptographic signature. The vulnerability enables a remote, unauthenticated attacker to create a forged token containing arbitrary identity claims, thereby gaining a fully authenticated technician session. In some configurations the flaw also permits bypass of multi‑factor authentication. The weakness is a missing signature verification and is classified as CWE‑347.
Affected Systems
The affected product is SimpleHelp by SimpleHelp, any installation using OIDC authentication on the vulnerable versions listed above. The CVE description does not specify a particular sub‑product or additional components, so any environment running the susceptible SimpleHelp releases should be considered at risk.
Risk and Exploitability
The CVSS score of 9.5 indicates a high severity with a full authentication bypass. The EPSS score is not available, but the vulnerability can be exploited remotely with no user interaction and no special privileges, making it accessible to a broad threat set. It is not listed in the CISA KEV catalog. Because the flaw allows an unauthenticated attacker to impersonate a technician or bypass MFA, the risk to confidentiality and integrity of the system is significant. The likely attack vector is a remote HTTP request to the OIDC authentication endpoint with a crafted JWT, exploiting the missing signature validation step.
OpenCVE Enrichment