قاعدة الثغرات (CVE)
CVE-2026-48558
تجاوز مصادقة OIDC في SimpleHelp
عند تهيئة مصادقة OIDC، تُقبل رموز الهوية المقدَّمة عند تسجيل الدخول دون التحقق من توقيعها، ما يتيح انتحال أي مستخدم في أداة الدعم عن بُعد.
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
المنتجات المتأثرة
| Product | الإصدارات المتأثرة | تم الإصلاح في |
|---|---|---|
| SimpleHelp | — | — |
التغطية على سيبرانا
—