Junglewise Threat Intelligence

CVE-2026-30457: Daylight Studio FuelCMS code injection in Dwoo parser

CVE-2026-30457 · Severity: critical · CVSS 9.8 · Published 2026-03-26

Technologies: Daylight Studio FuelCMS. Vendors: Daylight Studio.

Executive brief

Daylight Studio FuelCMS is a content management system used to build and manage websites. A critical security flaw in its template parsing component allows an attacker to run their own malicious code on the server. This could lead to a complete takeover of the website, theft of sensitive customer data, or a total service outage.

Technical details

A code injection vulnerability exists in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2. The issue stems from improper control of generation of code (CWE-94) within the Dwoo template engine integration, specifically allowing attackers to bypass security boundaries via crafted PHP code. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the vulnerable component, leading to arbitrary PHP code execution on the underlying server. This grants the attacker full system access under the context of the web server user. A third-party advisory and exploit details have been documented regarding the use of Dwoo escape sequences to achieve this execution.

Affected products

  • Daylight Studio FuelCMS 1.5.2

Timeline

  • 2026-03-26: disclosed
  • 2026-03-26: advisory

References

Related threats