Logic Flaw in GetSimple CMS Enables Unauthorized Admin Account Creation
CVE-2026-53952

9.8CRITICAL

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-53952?

GetSimple CMS, including its community edition, contains a logic flaw that permits unauthenticated attackers to create new administrator accounts. This vulnerability arises from a faulty deletion mechanism for the sensitive admin/setup.php file, which should be removed post-installation to prevent unauthorized access. Despite an automated security control intended to mitigate this risk, a bug in the system's self-exclusion logic enables the setup.php script to remain accessible. As a consequence, malicious actors can exploit this oversight to gain elevated privileges on the affected CMS versions. Currently, there are no patches available to fix this vulnerability.

Affected Version(s)

GetSimpleCMS <= 3.4.0a

GetSimpleCMS-CE <= 3.3.22

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.