CRITICAL
9.8 CVE-2026-53952 Published 11 Sept 2026
GetSimple CMS Admin Account Creation Flaw
Worried this affects one of your servers?
GetSimple CMS, a content management system, and its community edition (GetSimple CMS CE) are affected.
GetSimple CMS (v3.4.0a and below) and GetSimple CMS CE (v3.3.22 and below) contain a logic flaw that allows unauthenticated attackers to create a new administrator account.
The application's automated security control to delete the sensitive admin/setup.php file post-installation is bypassed due to a self-exclusion bug in the deletion logic, leaving the setup script accessible for unauthorized account creation.
Reference: CVE-2026-53952 on NVD
← Back to Security News