CVE-2026-56660
Deferred Deferred - Pending Action

Remote Code Execution in GetSimple CMS Community Edition

Vulnerability report for CVE-2026-56660, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
getsimple cms to 1.5 (exc)
getsimple cms_ce to 1.5 (exc)
getsimple cms 1.5
getsimple cms_ce 1.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects GetSimple CMS CE versions prior to 1.5. The UpdateCE.php file downloads a ZIP archive and extracts it into the web root without checking file types or paths. Attackers can exploit this to upload PHP files into accessible directories, achieving remote code execution. Directory traversal is also possible, allowing writes outside the intended directory.

Detection Guidance

Check if your GetSimple CMS CE version is below 1.5. Inspect web root directories for unexpected PHP files or unusual directory structures. Look for logs showing ZIP extraction processes or unauthorized file writes.

Impact Analysis

An attacker who tricks an authenticated admin into processing a malicious ZIP file can execute arbitrary code on the server. This could lead to full system compromise, data theft, or defacement. The attack requires user interaction but can be combined with other vulnerabilities like CSRF or SSRF.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or loss of data integrity, violating GDPR and HIPAA requirements for confidentiality and security. Organizations using vulnerable versions may face compliance violations and penalties.

Mitigation Strategies

Upgrade GetSimple CMS CE to version 1.5 or later immediately. Disable the UpdateCE plugin if not in use. Restrict write permissions to web root directories and monitor for suspicious file creation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56660. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart