Junglewise Threat Intelligence

CVE-2026-30460: Daylight Studio FuelCMS authenticated RCE in Blocks module

CVE-2026-30460 · Severity: high · CVSS 8.8 · Published 2026-04-07

Technologies: Daylight Studio FuelCMS. Vendors: Daylight Studio.

Executive brief

Daylight Studio FuelCMS, a content management system built on the CodeIgniter framework, contains a critical security flaw in its Blocks module. An attacker with basic user credentials can exploit this vulnerability to execute arbitrary code on the underlying server. This could lead to a complete takeover of the website, unauthorized access to sensitive data, and disruption of business operations.

Technical details

An authenticated remote code execution (RCE) vulnerability exists in Daylight Studio FuelCMS v1.5.2 within the Blocks module. The flaw is classified as a code injection vulnerability (CWE-94) where the application fails to properly neutralize or validate input used to generate code. An attacker with 'low' administrative privileges can leverage the network-reachable Blocks module to inject and execute arbitrary PHP code. This vulnerability allows for a total impact on confidentiality, integrity, and availability. While a proof-of-concept exists, the project is reportedly no longer in active development, and users are advised to migrate to supported platforms or implement strict access controls.

Affected products

  • Daylight Studio FuelCMS 1.5.2

Timeline

  • 2026-04-07: disclosed: Initial NVD publication date
  • 2026-04-09: advisory: CISA-ADP enrichment and CWE assignment

References