CVE-2026-53952
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installation. However, this control is neutralized by a self-exclusion bug within the deletion logic, leaving the setup script accessible for unauthorized account creation even after a legitimate installation is completed. As of time of publication, no known patched versions are available.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.33%
- CWE
- CWE-285, CWE-306, CWE-489
- Published
- 2026-09-11
- Last modified
- 2026-09-14
Affected products
- GetSimpleCMS-CE GetSimpleCMS-CE
- GetSimpleCMS GetSimpleCMS
Weakness type
Related vulnerabilities
- CVE-2026-66422 — Apache Tomcat: Servlet role references can bypass declarative role constraints
- CVE-2026-55166 — Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR
- CVE-2026-53548 — Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users
- CVE-2026-73644 — OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant
- CVE-2026-45052 — OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
- CVE-2026-48499 — Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
- CVE-2026-18367 — A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS
- CVE-2026-16279 — Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x