# SimpleHelp accepts unsigned OIDC tokens, MFA bypass

Source: https://startwithidentity.com/cves/cve-2026-48558/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

SimpleHelp (remote support, through 5.5.15 and 6.0 pre-release) accepted [OIDC](https://startwithidentity.com/glossary/oidc/) ID tokens without checking the signature. `alg:none` worked. A forged token is a login, and it skipped MFA. The vendor patched. A public proof of concept is out.

## Why it matters

Remote-support tools are privileged by design: they sit on admin workstations and jump boxes. An OIDC integration that does not verify the ID token is an MFA bypass with a support-tool blast radius. `alg:none` is a twenty-year-old JWT lesson. Seeing it in 2026 on a product that enterprises use to reach production is the story.

## What to do

- Patch SimpleHelp. If a public PoC exists and you were on 5.5.15 or earlier, review sessions and local accounts.
- Confirm your OIDC client rejects `alg:none` and rejects tokens whose `kid` is missing from your [JWKS](https://startwithidentity.com/glossary/jwks/).
- Do not treat "we federated MFA through OIDC" as MFA if the RP never verifies the token.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2026-48558](https://nvd.nist.gov/vuln/detail/CVE-2026-48558)
