{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53952","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-06-11T15:50:01.281Z","datePublished":"2026-09-11T19:23:30.889Z","dateUpdated":"2026-09-14T18:18:01.091Z"},"containers":{"cna":{"title":"GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw","problemTypes":[{"descriptions":[{"cweId":"CWE-285","lang":"en","description":"CWE-285: Improper Authorization","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-306","lang":"en","description":"CWE-306: Missing Authentication for Critical Function","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-489","lang":"en","description":"CWE-489: Active Debug Code","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"name":"https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-rw2c-w4mg-46g4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-rw2c-w4mg-46g4"}],"affected":[{"vendor":"GetSimpleCMS-CE","product":"GetSimpleCMS-CE","versions":[{"version":"<= 3.3.22","status":"affected"}]},{"vendor":"GetSimpleCMS","product":"GetSimpleCMS","versions":[{"version":"<= 3.4.0a","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-09-11T19:23:30.889Z"},"descriptions":[{"lang":"en","value":"GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installation. However, this control is neutralized by a self-exclusion bug within the deletion logic, leaving the setup script accessible for unauthorized account creation even after a legitimate installation is completed. As of time of publication, no known patched versions are available."}],"source":{"advisory":"GHSA-rw2c-w4mg-46g4","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-14T17:11:06.020188Z","id":"CVE-2026-53952","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-14T18:18:01.091Z"}}]}}