CVE-2026-56662
Deferred Deferred - Pending Action

CSRF to RCE in GetSimple CMS Community Edition

Vulnerability report for CVE-2026-56662, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session β€” with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
getsimple cms to 1.5 (exc)
getsimple cms_ce to 1.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) flaw in GetSimple CMS CE versions before 1.5. The UpdateCE update form lacked an anti-CSRF token, and the server did not verify request origin or tokens. An attacker could host a malicious page that auto-submits a forged POST request to the update endpoint. When an authenticated administrator visits the page, the server performs an attacker-directed download-and-deploy operation, leading to remote code execution.

Detection Guidance

Check if your GetSimple CMS CE version is below 1.5. Inspect network traffic for unauthorized POST requests to the UpdateCE endpoint. Look for unexpected file downloads or deployments in the CMS directory. Review server logs for suspicious administrator activity during updates.

Impact Analysis

If you are an administrator of GetSimple CMS CE using a vulnerable version, an attacker could trick you into visiting a malicious page. This could allow the attacker to execute arbitrary code on your server, potentially taking full control of your system, stealing data, or disrupting services.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or loss of data integrity, which are critical violations under GDPR and HIPAA. Organizations may face legal penalties, reputational damage, and loss of trust if exploited.

Mitigation Strategies

Upgrade GetSimple CMS CE to version 1.5 or later immediately. Disable the UpdateCE plugin if not in use. Implement network-level protections to block unauthorized POST requests to the update endpoint. Monitor for signs of compromise such as unexpected files or code execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56662. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart