
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30460 is an authenticated remote code execution (RCE) vulnerability in Daylight Studio FuelCMS v1.5.2, specifically within the Blocks module. The vulnerability was published on April 7, 2026, and affects only version 1.5.2 of FuelCMS, a CodeIgniter-based content management system that is no longer in active development. It carries a CVSS v3.1 base score of 8.8 (High), requiring only low-privilege authentication and no user interaction to exploit (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), meaning the Blocks module fails to properly neutralize or validate user-supplied input before incorporating it into executable code. An authenticated attacker with low privileges can submit crafted input through the Blocks module interface over the network, causing the application to execute arbitrary code server-side. No user interaction is required beyond the attacker's own authenticated session, and attack complexity is low. A reference document from pentest-tools.com (PTT-2025-027) is cited in relation to this vulnerability, though its content could not be fully extracted (GitHub Advisory, Feedly).
Successful exploitation allows an authenticated attacker with low privileges to execute arbitrary code on the affected FuelCMS server, resulting in high impact to confidentiality, integrity, and availability. This can lead to complete system compromise, unauthorized access to sensitive data stored in or accessible by the CMS, data theft, defacement, and potential lateral movement within the network infrastructure. Given that FuelCMS is no longer actively maintained, no future security patches from the vendor are expected beyond the current advisory (GitHub Advisory, Feedly).
A proof-of-concept reference (PTT-2025-027) is listed on pentest-tools.com, though the document's content was assessed as corrupted/binary and no functional exploit code was confirmed to be extractable. There is no evidence of active in-the-wild exploitation at this time, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (0.000160), indicating a low near-term exploitation probability. No threat actor attribution has been reported (GitHub Advisory, Feedly).
/fuel/ or CMS-specific headers)./fuel/login)./fuel/ admin panel; unexpected DNS lookups or HTTP requests initiated by the PHP/web server process./fuel/blocks/edit/ or similar) with unusually large or encoded payloads; PHP error logs referencing unexpected code evaluation or eval() calls.shell.php, cmd.php, or with randomized names); unexpected modification timestamps on core CMS files.bash, sh, curl, wget, or python; unexpected cron jobs added under the web server user account (GitHub Advisory, Feedly).A patch is referenced via GitHub Advisory GHSA-crp2-42r4-6427, though specific patched version numbers are not confirmed in available sources. Since FuelCMS is no longer actively maintained (as noted in the project's own README), organizations are strongly advised to migrate away from FuelCMS for production use. As interim mitigations: restrict access to the FuelCMS admin panel (/fuel/) to trusted IP addresses via network-level controls or web server configuration; disable the Blocks module if not required; and monitor logs for suspicious activity in the Blocks module. Review the GitHub Advisory for any available patching instructions (GitHub Advisory, FUEL-CMS Repo).
The vulnerability received limited public attention, with automated tracking by CVE aggregators and threat intelligence platforms. The FUEL-CMS GitHub repository itself carries a prominent warning that the project is no longer in active development and is not recommended for production use, which contextualizes the limited vendor response. No notable researcher commentary or significant media coverage has been identified beyond standard CVE database entries (FUEL-CMS Repo, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."