216.73.217.22

CVE-2026-27161

· Published 21/02/2026 00:16 · Modified 21/02/2026 00:16

Labels: CVE-2026-27161 2026-02-21CVE-2026-27161CWE-200[email protected]

Essential information

Published
21/02/2026 00:16
Modified
21/02/2026 00:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled (common in hardened or shared hosting environments), these protections are silently ignored, allowing unauthenticated attackers to list and download sensitive files including authorization.xml, which contains cryptographic salts and API keys. This issue does not have a fix at the time of publication.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
getsimple / getsimple cms cpe:2.3:a:getsimple:getsimple_cms:*:*:*:*:*:*:*:*

References