High severity8.3NVD Advisory· Published Apr 15, 2026· Updated Apr 20, 2026
CVE-2026-30461
CVE-2026-30461
Description
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule.
Affected products
1- cpe:2.3:a:thedaylightstudio:fuel_cms:1.5.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- pentest-tools.com/PTT-2025-028-Authenticated-RCE-via-Git-Submodules.pdfnvdExploitThird Party Advisory
- daylight.comnvdNot Applicable
- fuelcms.comnvdProduct
- github.com/daylightstudio/FUEL-CMS/blob/master/fuel/modules/fuel/controllers/Installer.phpnvdProduct
News mentions
0No linked articles in our index yet.