CVE-2026-48558 is a maximum-severity (CVSS 10.0) authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software. The flaw stems from a complete lack of cryptographic signature verification during the OpenID Connect (OIDC) identity provider (IdP) authentication flow.