CVE-2026-53953
Deferred Deferred - Pending Action

Authentication Bypass in GetSimple CMS via Predictable Password Reset

Vulnerability report for CVE-2026-53953, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
getsimple cms 3.3.22
getsimple cms_ce 3.3.22

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
CWE-338 The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects GetSimple CMS Community Edition versions up to 3.3.22. The password reset endpoint can be accessed without authentication. When a reset is requested for an existing user, a temporary password is generated using PHP's rand() function seeded with microtime(). The limited seed space allows attackers to predict possible passwords. The admin login lacks rate limiting, enabling brute-force attacks to take over the administrator account.

Detection Guidance

Check if your GetSimple CMS CE version is 3.3.22 or earlier. Inspect server logs for unusual password reset requests or failed login attempts targeting admin accounts. Monitor for unauthorized administrative actions or content changes.

Impact Analysis

An attacker could gain full administrative access to the CMS. This allows unauthorized content changes, user management abuse, and potential further system compromise. Since the attack is remote and requires no prior access, any exposed instance of GetSimple CMS CE up to version 3.3.22 is at risk.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Administrator account takeover may result in exposure of sensitive user data, triggering mandatory breach notifications and potential fines under these regulations.

Mitigation Strategies

Upgrade to the latest version of GetSimple CMS CE if available. Implement rate limiting and account lockout on the admin login endpoint. Replace the insecure password reset mechanism with cryptographically secure methods like random_int(). Disable password reset functionality temporarily if no patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53953. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart