Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installation. However, this control is neutralized by a self-exclusion bug within the deletion logic, leaving the setup script accessible for unauthorized account creation even after a legitimate installation is completed. As of time of publication, no known patched versions are available.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated admin account creation leading to full CMS control
Action: Apply Mitigation
AI Analysis

Impact

The vulnerability stems from a logic flaw in the automated deletion routine that is meant to remove a sensitive script after installation. The flaw neutralizes the removal process, leaving the setup script in the web root. Because the script remains accessible, an attacker can create a fully privileged administrator account without needing prior authentication, granting unrestricted access to content management, configuration, and potential code execution. The issue exists in GetSimple CMS and its community edition.

Affected Systems

GetSimpleCMS-CE versions 3.3.22 and earlier, and GetSimpleCMS versions 3.4.0a and earlier, are impacted. No patched releases have been issued at the time of this advisory.

Risk and Exploitability

The CVSS score of 9.8 marks this as a critical vulnerability. The EPSS score of less than 1% indicates a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it simply by accessing the exposed setup script, creating an administrator account, and thereafter performing any action allowed by that role. The impact spans confidentiality, integrity, and availability of the CMS system.

Generated by OpenCVE AI on September 21, 2026 at 04:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Immediately remove or rename the admin/setup.php file from the public directory.
  • Restrict access to any remaining setup scripts by IP filtering or firewall rules to trusted addresses only.
  • Once a vendor patch becomes available, apply it without delay to restore proper delete logic.

Generated by OpenCVE AI on September 21, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Get-simple
Get-simple getsimplecms
Getsimple-ce
Getsimple-ce getsimple Cms
Vendors & Products Get-simple
Get-simple getsimplecms
Getsimple-ce
Getsimple-ce getsimple Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installation. However, this control is neutralized by a self-exclusion bug within the deletion logic, leaving the setup script accessible for unauthorized account creation even after a legitimate installation is completed. As of time of publication, no known patched versions are available.
Title GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw
Weaknesses CWE-285
CWE-306
CWE-489
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Get-simple Getsimplecms
Getsimple-ce Getsimple Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:18:01.091Z

Reserved: 2026-06-11T15:50:01.281Z

Link: CVE-2026-53952

cve-icon Vulnrichment

Updated: 2026-09-14T17:11:07.019Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T20:17:14.060

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-53952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-489

    Active Debug Code