CRITICAL 9.8 CVE-2026-53952 Published 11 Sept 2026

GetSimple CMS Admin Account Creation Flaw

Worried this affects one of your servers?

GetSimple CMS, a content management system, and its community edition (GetSimple CMS CE) are affected.

GetSimple CMS (v3.4.0a and below) and GetSimple CMS CE (v3.3.22 and below) contain a logic flaw that allows unauthenticated attackers to create a new administrator account.

The application's automated security control to delete the sensitive admin/setup.php file post-installation is bypassed due to a self-exclusion bug in the deletion logic, leaving the setup script accessible for unauthorized account creation.

Reference: CVE-2026-53952 on NVD

← Back to Security News