Junglewise Threat Intelligence

CVE-2026-30462: Daylight Studio FuelCMS path traversal in Blocks module

CVE-2026-30462 · Severity: medium · CVSS 4.3 · Published 2026-04-27

Technologies: Daylight Studio FuelCMS. Vendors: Daylight Studio.

Executive brief

Daylight Studio FuelCMS is a content management system used to build and manage websites. A security vulnerability in its Blocks module allows an attacker with basic user permissions to access files on the server that they should not be able to see. This could lead to the exposure of sensitive configuration data or system information, potentially compromising the security of the entire website.

Technical details

A path traversal vulnerability (CWE-22) exists in the Blocks module of Daylight Studio FuelCMS v1.5.2. The vulnerability is located within the 'fuel/modules/fuel/controllers/Blocks.php' component, where insufficient validation of user-supplied input allows for directory traversal sequences. An attacker with low-privileged (PR:L) network access can exploit this flaw to bypass directory restrictions and read arbitrary files on the underlying file system. This can result in the disclosure of sensitive information such as configuration files or system credentials. While a proof-of-concept exists, no official patch is explicitly detailed in the advisory, though users are encouraged to monitor the official GitHub repository for updates.

Affected products

  • Daylight Studio FuelCMS 1.5.2

Timeline

  • 2026-04-27: disclosed
  • 2026-04-27: advisory

References