CVE-2026-56661: GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint

Published Oct 1, 2026
·
Updated

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with filegetcontents() after only format validation (FILTERVALIDATEURL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.

Affected Software

1 affected component
GetSimple CMS GetSimple CMS CE<1.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GetSimple CMS CE to a version that resolves this vulnerability.

    Fixed in 1.5

Event History

Oct 1, 2026
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be able to submit the update form. The vulnerability has network attack vector and low attack complexity, but it requires high privileges and user interaction according to the supplied severity vector.

2

What can an attacker access through the vulnerable endpoint?

The server can be induced to request arbitrary destinations because only URL format validation is performed. This includes internal-only services and cloud metadata endpoints such as 169.254.169.254, and the response can be retrieved through the web-accessible /Tmpfile.zip file when it is not a valid ZIP.

3

Which versions are affected and what is the remediation?

GetSimple CMS CE versions prior to 1.5 are affected. Upgrade to version 1.5, which patches the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203