Impact
SimpleHelp versions 5.5.15 and earlier, along with pre‑release 6.0 releases, allow an attacker to bypass authentication by supplying an OIDC identity token that the server accepts without checking its cryptographic signature. This flaw lets a remote, unauthenticated attacker forge arbitrary identity claims and obtain a fully authenticated technician session. In certain setups the bypass also defeats multi‑factor authentication. The weakness is a missing signature verification and is classified as CWE‑347.
Affected Systems
Any installation of SimpleHelp utilizing OIDC authentication on the vulnerable releases is at risk. The affected releases are 5.5.15 and earlier, and pre‑release 6.0 versions. Any product identified as SimpleHelp by SimpleHelp that uses this authentication path must be considered vulnerable.
Risk and Exploitability
The CVSS score of 9.5 signals a high‑severity authentication bypass, and the EPSS score of 11% indicates a moderate exploitation probability. Attackers can exploit the flaw remotely, with no user interaction and no special privileges, making it accessible to a wide threat set. The vulnerability is listed in the CISA KEV catalog. An attacker can send a crafted JWT to the OIDC authentication endpoint, taking advantage of the missing signature validation to hijack a technician session.
OpenCVE Enrichment