Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53952— GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw

Quick assessment

Affected
GetSimpleCMS-CE GetSimpleCMS-CE
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GetSimple CMS 是一种内容管理系统(CMS),而 GetSimple CMS CE 是该 CMS 的社区版。GetSimple CMS(v3.4.0a 及以下版本)和 GetSimpleCMS-CE(v3.3.22 及以下版本)中存在一个逻辑缺陷,使得未经身份验证的攻击者能够创建新的管理员账户。 该应用程序具备一项自动化安全控制机制,旨在在安装完成后删除敏感文件 。然而,删除逻辑中存在的“自我排除”缺陷使这一控制机制失效,导致安装完成后,安装脚本仍然可以访问,从而允许非授权的用户创建账户。 截至本公告发

CVSS 9.8 · Critical EPSS 0.22% · P45

Affected Version Matrix 2

VendorProduct Version RangeStatus
GetSimpleCMS GetSimpleCMS <= 3.4.0a affected
GetSimpleCMS-CE GetSimpleCMS-CE <= 3.3.22 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53952

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw
Source: CVE Program / CVE List V5
Vulnerability Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installation. However, this control is neutralized by a self-exclusion bug within the deletion logic, leaving the setup script accessible for unauthorized account creation even after a legitimate installation is completed. As of time of publication, no known patched versions are available.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GetSimpleCMS-CE GetSimpleCMS-CE <= 3.3.22 -
GetSimpleCMS GetSimpleCMS <= 3.4.0a -

II. Public POCs for CVE-2026-53952

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53952

登录查看更多情报信息。

Other References for CVE-2026-53952 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53952

No comments yet


Leave a comment