CVE-2026-30461 is an authenticated remote code execution vulnerability affecting Daylight Studio FuelCMS version 1.5.2, exploitable through the /controllers/Installer.php file via the add_git_submodule function. The vulnerability requires valid user credentials to exploit but can be executed remotely over the network with minimal complexity once authenticated access is obtained. With a CVSS score of 8.3 (HIGH), the vulnerability carries significant risk due to its potential for complete system compromise, including high confidentiality and integrity impacts with some availability concerns. The vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and is not actively tracked on the Hot List, indicating no evidence of widespread active exploitation at this time. The EPSS score of 0.0033 suggests this vulnerability has lower relative priority compared to the broader CVE landscape, though the authentication requirement may be limiting opportunistic exploitation attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.2CPE matchmatch criteria | cpe:2.3:a:thedaylightstudio:fuel_cms:1.5.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.