PT-2026-21325 · Apache+1 · Apache+1

Twinson333

·

Published

2026-02-20

·

Updated

2026-02-24

·

CVE-2026-27161

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GetSimple CMS (affected versions not specified)
Description GetSimple CMS is a content management system. All versions of GetSimple CMS depend on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled, a common configuration in hardened or shared hosting environments, these protections are silently ignored. This allows unauthenticated attackers to list and download sensitive files, including authorization.xml, which contains cryptographic salts and API keys. The authorization.xml file contains sensitive information that could be used to compromise the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27161
GHSA-F63G-XH6J-Q56G

Affected Products

Apache
Getsimple Cms