Logic Flaw in GetSimple CMS Enables Unauthorized Admin Account Creation
CVE-2026-53952
9.8CRITICAL
What is CVE-2026-53952?
GetSimple CMS, including its community edition, contains a logic flaw that permits unauthenticated attackers to create new administrator accounts. This vulnerability arises from a faulty deletion mechanism for the sensitive admin/setup.php file, which should be removed post-installation to prevent unauthorized access. Despite an automated security control intended to mitigate this risk, a bug in the system's self-exclusion logic enables the setup.php script to remain accessible. As a consequence, malicious actors can exploit this oversight to gain elevated privileges on the affected CMS versions. Currently, there are no patches available to fix this vulnerability.
Affected Version(s)
GetSimpleCMS <= 3.4.0a
GetSimpleCMS-CE <= 3.3.22
