
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30458 is a mail splitting (email header injection) vulnerability in Daylight Studio FuelCMS v1.5.2 that allows unauthenticated attackers to exfiltrate users' password reset tokens, enabling account takeover. The vulnerability was published on March 26, 2026, and affects only FuelCMS version 1.5.2. It carries a CVSS v3.1 base score of 9.1 (Critical) with high confidentiality and integrity impact and no authentication required (Red Hat CVE, ENISA EUVD). Notably, the FUEL-CMS project is no longer in active development and is not recommended for production use (FUEL-CMS GitHub).
The root cause is classified under CWE-620 (Unverified Password Change), stemming from insufficient validation of user-supplied input in the password reset email functionality. By injecting crafted email header content (a mail splitting or email header injection attack), an unauthenticated attacker can manipulate the outgoing password reset email to redirect or duplicate the message — including the embedded reset token — to an attacker-controlled address. No authentication, user interaction, or special privileges are required for exploitation, and the attack is conducted entirely over the network (Red Hat CVE, ENISA EUVD). A technical write-up is referenced in a pentest advisory PDF (Pentest Tools Advisory), though its content was not fully extractable.
Successful exploitation allows an unauthenticated attacker to intercept valid password reset tokens for any user account, enabling complete account takeover without the victim's knowledge or interaction. This results in high confidentiality impact (token and credential disclosure) and high integrity impact (unauthorized account access and potential data modification), with no availability impact. Given that FuelCMS manages web content, a compromised administrator account could lead to full CMS compromise, content defacement, or further server-side attacks (ENISA EUVD, Red Hat CVE).
No confirmed working exploit has been publicly demonstrated; the referenced pentest advisory PDF was found to contain only binary/compressed data with no extractable exploit code or steps. The EPSS score is very low at approximately 0.018%, indicating a low probability of active exploitation in the near term. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (ENISA EUVD, Pentest Tools Advisory).
%0A, %0D%0A) followed by additional email headers (e.g., Cc: or Bcc: pointing to an attacker-controlled address), exploiting the lack of input sanitization./fuel/login/forgot_password) containing URL-encoded newline characters (%0a, %0d, %0d%0a) in email input fields.No official patch has been released for FuelCMS v1.5.2, and the project is explicitly no longer in active development and not recommended for production use (FUEL-CMS GitHub). Organizations still running FuelCMS should migrate to an actively maintained CMS as the primary remediation. As interim mitigations: implement strict server-side validation and sanitization of all email input fields to reject or strip newline and carriage return characters; enforce single-use, short-lived password reset tokens; apply rate limiting on password reset requests; and monitor for anomalous password reset activity (ENISA EUVD).
The vulnerability received limited but notable coverage across security aggregation platforms including CVEFeed, VulDB, and Radar/OffSeq shortly after publication. A brief mention appeared on Mastodon via @thehackerwire. No major vendor statements, researcher deep-dives, or mainstream media coverage have been identified beyond automated CVE tracking (ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."