Unrestricted File Access in GetSimple CMS Affects Sensitive Data Exposure
CVE-2026-27161

8.7HIGH

Key Information:

Vendor
CVE Published:
20 February 2026

What is CVE-2026-27161?

GetSimple CMS, a widely-used content management system, has a significant security issue related to its reliance on .htaccess files for controlling access to sensitive directories, such as /data/ and /backups/. In scenarios where the Apache AllowOverride directive is set to disabled, which is common in shared or tightly secured hosting environments, these essential protections become ineffective. This flaw permits unauthenticated attackers to not only list files but also download sensitive data, including the crucial authorization.xml file that contains cryptographic salts and API keys. Currently, there is no fix available for this issue, exposing users to considerable risk.

Affected Version(s)

GetSimpleCMS-CE <= 3.3.22

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.