Junglewise Threat Intelligence

CVE-2026-30458: Daylight Studio FuelCMS password reset token exfiltration via mail splitting

CVE-2026-30458 · Severity: critical · CVSS 9.1 · Published 2026-03-26

Technologies: Daylight Studio FuelCMS. Vendors: Daylight Studio.

Executive brief

Daylight Studio FuelCMS, a content management system used for building websites, contains a critical security flaw in its password reset process. An attacker can exploit this to intercept the secret tokens used to reset user passwords, potentially allowing them to take over any user account, including administrative ones. This could lead to unauthorized access to sensitive website data and full control over the site's content.

Technical details

A vulnerability in Daylight Studio FuelCMS v1.5.2 allows for account takeover via a mail splitting attack during the password reset process. The flaw, classified as CWE-620 (Unverified Password Change), stems from improper handling of email inputs, potentially through an email array injection or header manipulation. A remote, unauthenticated attacker can exploit this to redirect or BCC password reset emails to an attacker-controlled address, thereby obtaining the reset token. With this token, the attacker can reset the password for any user account. The project is currently marked as no longer in active development on GitHub, suggesting a patch may not be forthcoming.

Affected products

  • Daylight Studio FuelCMS 1.5.2

Timeline

  • 2026-03-26: disclosed: Initial NVD publication date
  • 2026-07-04: advisory: Last modified date in NVD record

References

Related threats