PT-2026-30849 · Daylight Studio · Fuel Cms

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-30460

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Daylight Studio FuelCMS version 1.5.2
Description Daylight Studio FuelCMS version 1.5.2 contains an authenticated remote code execution (RCE) issue in the Blocks module. This allows for the execution of arbitrary code remotely by an authenticated attacker.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Blocks module to minimize the risk of exploitation.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30460

Affected Products

Fuel Cms