CVE-2026-30460
Fuel CMS vulnerability analysis and mitigation

Overview

CVE-2026-30460 is an authenticated remote code execution (RCE) vulnerability in Daylight Studio FuelCMS v1.5.2, specifically within the Blocks module. The vulnerability was published on April 7, 2026, and affects only version 1.5.2 of FuelCMS, a CodeIgniter-based content management system that is no longer in active development. It carries a CVSS v3.1 base score of 8.8 (High), requiring only low-privilege authentication and no user interaction to exploit (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), meaning the Blocks module fails to properly neutralize or validate user-supplied input before incorporating it into executable code. An authenticated attacker with low privileges can submit crafted input through the Blocks module interface over the network, causing the application to execute arbitrary code server-side. No user interaction is required beyond the attacker's own authenticated session, and attack complexity is low. A reference document from pentest-tools.com (PTT-2025-027) is cited in relation to this vulnerability, though its content could not be fully extracted (GitHub Advisory, Feedly).

Impact

Successful exploitation allows an authenticated attacker with low privileges to execute arbitrary code on the affected FuelCMS server, resulting in high impact to confidentiality, integrity, and availability. This can lead to complete system compromise, unauthorized access to sensitive data stored in or accessible by the CMS, data theft, defacement, and potential lateral movement within the network infrastructure. Given that FuelCMS is no longer actively maintained, no future security patches from the vendor are expected beyond the current advisory (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept reference (PTT-2025-027) is listed on pentest-tools.com, though the document's content was assessed as corrupted/binary and no functional exploit code was confirmed to be extractable. There is no evidence of active in-the-wild exploitation at this time, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (0.000160), indicating a low near-term exploitation probability. No threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing FuelCMS v1.5.2 instances using web search engines, Shodan, or Censys by fingerprinting the CMS (e.g., default paths like /fuel/ or CMS-specific headers).
  2. Obtain credentials: Acquire low-privilege authenticated credentials via phishing, credential stuffing, or brute force against the FuelCMS admin login panel (typically at /fuel/login).
  3. Access the Blocks module: Log in to the FuelCMS admin panel and navigate to the Blocks module, which allows creation and editing of content blocks.
  4. Inject malicious code: Submit a crafted payload within a block's content or configuration field that exploits the lack of input sanitization to inject server-side executable code (e.g., PHP code if the CMS evaluates block content as code).
  5. Achieve remote code execution: Trigger the injected block to be rendered or processed by the server, causing arbitrary code execution under the web server's process context, enabling reverse shell establishment, data exfiltration, or further post-exploitation activity (GitHub Advisory, Feedly).

Indicators of compromise

  • Network: Unusual outbound connections from the web server process to external IPs following authenticated access to the /fuel/ admin panel; unexpected DNS lookups or HTTP requests initiated by the PHP/web server process.
  • Logs: Web server access logs showing POST requests to Blocks module endpoints (e.g., /fuel/blocks/edit/ or similar) with unusually large or encoded payloads; PHP error logs referencing unexpected code evaluation or eval() calls.
  • File System: New or modified PHP files in the FuelCMS web root or upload directories, particularly web shells (e.g., files named shell.php, cmd.php, or with randomized names); unexpected modification timestamps on core CMS files.
  • Process: Unusual child processes spawned by the web server (e.g., Apache/Nginx/PHP-FPM) such as bash, sh, curl, wget, or python; unexpected cron jobs added under the web server user account (GitHub Advisory, Feedly).

Mitigation and workarounds

A patch is referenced via GitHub Advisory GHSA-crp2-42r4-6427, though specific patched version numbers are not confirmed in available sources. Since FuelCMS is no longer actively maintained (as noted in the project's own README), organizations are strongly advised to migrate away from FuelCMS for production use. As interim mitigations: restrict access to the FuelCMS admin panel (/fuel/) to trusted IP addresses via network-level controls or web server configuration; disable the Blocks module if not required; and monitor logs for suspicious activity in the Blocks module. Review the GitHub Advisory for any available patching instructions (GitHub Advisory, FUEL-CMS Repo).

Community reactions

The vulnerability received limited public attention, with automated tracking by CVE aggregators and threat intelligence platforms. The FUEL-CMS GitHub repository itself carries a prominent warning that the project is no longer in active development and is not recommended for production use, which contextualizes the limited vendor response. No notable researcher commentary or significant media coverage has been identified beyond standard CVE database entries (FUEL-CMS Repo, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Fuel CMS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-30460HIGH8.8
  • Fuel CMS logoFuel CMS
  • cpe:2.3:a:thedaylightstudio:fuel_cms
NoNoApr 07, 2026
CVE-2026-30461HIGH8.3
  • Fuel CMS logoFuel CMS
  • cpe:2.3:a:thedaylightstudio:fuel_cms
NoNoApr 15, 2026
CVE-2026-30463HIGH7.7
  • Fuel CMS logoFuel CMS
  • cpe:2.3:a:thedaylightstudio:fuel_cms
NoNoMar 26, 2026
CVE-2021-47980HIGH7.1
  • Fuel CMS logoFuel CMS
  • cpe:2.3:a:thedaylightstudio:fuel_cms
NoYesMay 16, 2026
CVE-2026-30459HIGH7.1
  • Fuel CMS logoFuel CMS
  • cpe:2.3:a:thedaylightstudio:fuel_cms
NoNoApr 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management