CVE-2026-27161Disclosure(getsimple-ce / getsimple_cms)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch getsimple-ce getsimple_cms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled (common in hardened or shared hosting environments), these protections are silently ignored, allowing unauthenticated attackers to list and download sensitive files including authorization.xml, which contains cryptographic salts and API keys. This issue does not have a fix at the time of publication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • getsimple_cms

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-22); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
getsimple_cms

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-21: 1Mentions · 2026-02-22: 2Mentions · 2026-03-07: 1Patch / Workaround · 2026-02-21: 1Technical Details · 2026-02-21: 102-2102-2203-07
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-211
Patch1
2026-02-222
Disclosure1General1
2026-03-071
Disclosure1
Full discourse4 posts
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    How I found CVE-2026–27161 (Sensitive Disclosure) | Cyber Tamarin https://cybertamarin.medium.com/how-i-found-cve-2026-27161-sensitive-disclosure-cyber-tamarin-9b2e62dac238?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The post announces the discovery of CVE‑2026‑27161 but offers no technical details, PoC, or patch information.

    01112111.5K
    40.2K followersView on X
  • Antony Esthak Twinson@Twinson_333
    Disclosure

    How I found CVE-2026–27161 (Sensitive Disclosure) | Cyber Tamarin https://medium.com/p/how-i-found-cve-2026-27161-sensitive-disclosure-cyber-tamarin-9b2e62dac238?source=social.tw

    Post summary

    The post announces the discovery of CVE-2026‑27161 and explains how it was found, but provides no details on exploitation, patches, or technical specifics.

    0000038
    6 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    General

    "How I found CVE-2026–27161 (Sensitive Disclosure) | Cyber Tamarin" by Cyber Tamarin #BugBounty #Cybersecurity #Hacking #InfoSec https://cybertamarin.medium.com/how-i-found-cve-2026-27161-sensitive-disclosure-cyber-tamarin-9b2e62dac238

    Post summary

    The text only references the discovery of CVE-2026-27161 without providing additional details or actionable information.

    0000061
    478 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-27161: GetSimple CMS lets anyone browse /data & /backups when Apache AllowOverride is off, leaking salts, API keys and site content. Move those dirs outside webroot or add app-level access controls now. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-27161 #infosec #WebSecurity #CMS

    Post summary

    The tweet announces CVE-2026-27161, details how GetSimple CMS exposes sensitive directories when AllowOverride is off, and provides a practical workaround (move directories or enforce access controls).

    0000064
    50 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetsimple-cegetsimple_cms---

Explore more