OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-56662

CRITICAL · CVSS 9.6 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

GetSimple CMS versions prior to 1.5 are vulnerable to a critical remote code execution flaw due to the absence of anti-CSRF tokens and request-origin verification in the UpdateCE update form. An attacker can exploit this vulnerability by tricking an authenticated administrator into visiting a malicious page, leading to unauthorized code deployment within the administrator's session. Organizations using GetSimple CMS should prioritize upgrading to version 1.5 or later to mitigate this severe security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56662
Severity
CRITICAL
CVSS
9.6
EPSS
0.22%

Original NVD Description

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.