سيبرانا

قاعدة الثغرات (CVE)

CVE-2026-48558

تجاوز مصادقة OIDC في SimpleHelp

حرجةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد

عند تهيئة مصادقة OIDC، تُقبل رموز الهوية المقدَّمة عند تسجيل الدخول دون التحقق من توقيعها، ما يتيح انتحال أي مستخدم في أداة الدعم عن بُعد.

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

المنتجات المتأثرة

Productالإصدارات المتأثرةتم الإصلاح في
SimpleHelp

التغطية على سيبرانا