CVE-2026-48558 + CVE-2026-48303: Two CVSS 10.0 Criticals — SimpleHelp OIDC Bypass and Adobe Campaign RCE
Two CVSS 10.0 vulnerabilities from June 2026: SimpleHelp authentication bypass via OIDC token validation failure and Adobe Campaign Classic RCE via incorrect authorization.
Two separate CVSS 10.0 vulnerabilities landed in the same week. CVE-2026-48558 is a complete authentication bypass in SimpleHelp’s OIDC flow. CVE-2026-48303 is an incorrect authorization bug in Adobe Campaign Classic that allows arbitrary code execution. Both have Swiss Post E-Voting in scope at €230k max.
CVE-2026-48558: SimpleHelp OIDC authentication bypass
Published: 2026-06-12
CVSS: 10.0 (Critical)
Affected: SimpleHelp ≤ 5.5.15 and 6.0 pre-release builds
What SimpleHelp is
SimpleHelp is a self-hosted remote support platform — think a self-managed TeamViewer or ConnectWise alternative. IT teams run it on-premise for technician-to-end-user support sessions. It handles file transfers, remote desktop access, and often has administrative access to the machines it manages.
That makes it a high-value target. Compromise a SimpleHelp server and you potentially get an authenticated pathway into every endpoint the support team manages.
How the OIDC bypass works
When OIDC authentication is configured (typically pointing at Okta, Azure AD, or Google Workspace), SimpleHelp is supposed to validate the identity token returned by the identity provider — checking the signature, expiry, audience, and issuer claims before granting access.
In versions 5.5.15 and prior, that validation is bypassed. The implementation accepts a token and extracts the identity claims without properly verifying the token’s cryptographic signature against the identity provider’s public keys.
The practical consequence: an attacker can craft a valid-looking JWT with arbitrary claims — including admin role claims — sign it with their own key (or not sign it at all using alg: none), and present it to SimpleHelp as a legitimate OIDC token. SimpleHelp reads the claims and grants the access level they describe.
Attack shape:
1. Target has SimpleHelp configured with OIDC authentication
2. Attacker crafts JWT: { "sub": "attacker", "role": "admin", "email": "[email protected]" }
3. Signs with any key (or uses alg:none)
4. Sends token to SimpleHelp OIDC callback endpoint
5. SimpleHelp grants admin session without validating signature
Horizon3.ai published indicators of compromise alongside their disclosure — see their writeup for detection signatures.
Detection: are you running a vulnerable version?
# Check SimpleHelp server version via the version endpoint (no auth required on most installs)
curl -s https://your-simplehelp.example.com/version
# Check the server admin panel version indicator
# Admin > System > About
Version 5.5.15 and below = vulnerable. Version 6.0 pre-release builds before the May 2026 security update are also affected.
Patch: Simple-Help released a fix in their May 2026 security update. Upgrade to 5.5.16+ or the current 6.0 release build.
Bug bounty angle
SimpleHelp instances aren’t typically listed explicitly in programs, but they show up as in-scope assets under IT infrastructure and support tooling categories.
| Program | Max bounty |
|---|---|
| Swiss Post E-Voting | €230,000 |
| Doctolib | €50,000 |
For Doctolib, SimpleHelp would need to appear in their in-scope asset list. Swiss Post E-Voting has broad infrastructure scope — check the current program definition on Intigriti.
CVE-2026-48303: Adobe Campaign Classic arbitrary code execution
Published: 2026-06-09
CVSS: 10.0 (Critical)
Affected: Adobe Campaign Classic (ACC) ≤ 7.4.3 build 9394
What Adobe Campaign Classic is
Adobe Campaign Classic is an enterprise marketing automation platform — email campaigns, SMS, push notifications, audience segmentation. Large enterprises use it to manage customer communications at scale. It’s not a niche product: Adobe Campaign has millions of users globally, and ACC 7.x is widely deployed in enterprise environments.
The vulnerability: incorrect authorization → RCE
Adobe’s advisory describes this as an “Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.” The CVSS 10.0 score (no privileges required, network-accessible) means the current user context isn’t a meaningful constraint — it leads to system-level access.
The pattern here is authorization logic that fails to enforce permission checks on a code-execution pathway. Campaign Classic supports server-side JavaScript execution for workflow automation and data transformation. The likely failure mode is that an API endpoint or workflow trigger that should require an authenticated administrator session is instead accessible without valid authorization — allowing an unauthenticated or low-privileged caller to inject and execute arbitrary server-side JavaScript.
Server-side JavaScript in Campaign Classic runs with the privileges of the ACC application service account. On-premise deployments often run that account with broad file system and database access, which makes the RCE impact significantly higher than “code runs as a web app user.”
What to look for
Campaign Classic exposes several API surfaces worth examining:
# Probe for exposed Campaign Classic endpoints
# The SOAP API is commonly exposed and worth checking version headers
curl -s -I https://campaign.target.example.com/nl/jsp/soaprouter.jsp
# Check for exposed Tomcat admin interface (often misconfigured)
curl -s https://campaign.target.example.com/manager/
# nl/jsp/ paths expose various Campaign functions
# Test for unauthenticated access to workflow/script execution endpoints
curl -s https://campaign.target.example.com/nl/jsp/
# Check HTTP response headers for version disclosure
curl -I https://campaign.target.example.com/r/test
Version check:
Campaign Classic 7.4.3 build 9394 and earlier are affected. Version information appears in the Server header or via the admin console (Administration > Platform > About).
Remediation
Adobe published the fix in APSB26-66. Upgrade to a build above 9394. Organizations running on-premise ACC should prioritize this — cloud-hosted Campaign instances are patched by Adobe automatically, but self-managed deployments are not.
Interim mitigations while patching:
- Restrict ACC server access to known IP ranges via network ACLs
- Audit exposed nl/jsp/ endpoints and disable unused ones
- Review ACC service account permissions — it should not have local admin or unrestricted database access
- Enable audit logging on ACC API access
Bug bounty: Swiss Post E-Voting
Swiss Post E-Voting runs at €230k maximum and has broad infrastructure scope on Intigriti. Campaign Classic exposure in their environment would qualify for the highest severity tier. That said, verify the specific asset is in scope before testing — large enterprise platforms sometimes appear as out-of-scope legacy systems.
Combined: what this week tells you
Two CVSS 10.0 vulnerabilities affecting enterprise infrastructure in the same week isn’t unusual — but the common thread here is authentication/authorization failures on code execution pathways. Both CVEs follow the same fundamental pattern: a service accepts input and executes something privileged without properly verifying who’s asking.
For hunters: enterprise IT support tools (SimpleHelp, TeamViewer alternatives) and enterprise marketing platforms (Campaign, Marketo, Eloqua) are consistently underexamined compared to web app targets. They’re complex, often self-hosted, and frequently configured by IT teams who prioritize uptime over hardening. If a program has broad infrastructure scope, checking what support and marketing automation tooling they run is a reliable way to find overlooked attack surface.
For context on how to evaluate and prioritize CVEs like these as they drop, see the CVE opportunity analysis for June 2026. The best CVE intelligence tools for bug bounty covers how to stay on top of new disclosures before the field gets crowded.