Unrestricted File Access in GetSimple CMS Affects Sensitive Data Exposure
CVE-2026-27161
8.7HIGH
What is CVE-2026-27161?
GetSimple CMS, a widely-used content management system, has a significant security issue related to its reliance on .htaccess files for controlling access to sensitive directories, such as /data/ and /backups/. In scenarios where the Apache AllowOverride directive is set to disabled, which is common in shared or tightly secured hosting environments, these essential protections become ineffective. This flaw permits unauthenticated attackers to not only list files but also download sensitive data, including the crucial authorization.xml file that contains cryptographic salts and API keys. Currently, there is no fix available for this issue, exposing users to considerable risk.
Affected Version(s)
GetSimpleCMS-CE <= 3.3.22
