Authentication bypass in SimpleHelp OIDC authentication flow. When OIDC is configured, identity tokens submitted during login are accepted without verifying cryptographic signatures, allowing remote unauthenticated attackers to submit forged tokens with arbitrary identity claims to obtain fully authenticated technician sessions. May also allow MFA bypass. Actively exploited to deploy Djinn Stealer targeting Windows, macOS, and Linux.
Apply vendor security updates immediately per SimpleHelp advisory. Discontinue use if mitigations unavailable per CISA BOD 26-04. Review SimpleHelp authentication logs for suspicious OIDC token submissions. Implement network-based access controls as compensating control.
Source: CISA KEV • Published: 2026-06-15
Unpatched prompt injection vulnerability in Model Context Protocol (MCP) implementations affecting multiple AI IDEs. Requires only .mcp.json and settings file in malicious repository. Auto-approved MCP server spawns as unsandboxed OS process with full user privileges and access to SSH keys, cloud credentials, and source code. Zero-click exploitation in CI/CD environments. Represents OWASP LLM01 vulnerability class.
Review every repository for .mcp.json files before opening. Disable auto-approval in agent settings. Restrict MCP server execution in CI environments. Implement mandatory code review for MCP configuration changes. Deploy until vendor patches are available.
Source: Adversa AI • Published: 2026-05-07
CVE-2026-48558: Authentication bypass in SimpleHelp OIDC authentication flow. When OIDC is configured, identity tokens submitted during login are accepted without verifying cryptographic signatures, allowing remote unauthenticated attackers to submit forged tokens with arbitrary identity claims to obtain fully authenticated technician sessions. May also allow MFA bypass. Actively exploited to deploy Djinn Stealer targeting Windows, macOS, and Linux.