CVE-2026-30458 is a critical vulnerability (CVSS 9.1) affecting Daylight Studio FuelCMS v1.5.2, allowing attackers to exfiltrate users' password reset tokens. This is achieved through a mail splitting attack (CWE-620) with a network attack vector and low complexity. Successful exploitation results in high confidentiality and integrity impacts, potentially leading to account compromise. Currently, there is no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB. While it has garnered minor community discussion, it is not listed on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.2CPE matchmatch criteria | cpe:2.3:a:thedaylightstudio:fuel_cms:1.5.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.