CVE-2026-30459: High severity Daylight Studio FuelCMS vulnerability
Published Apr 16, 2026
·Updated
An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.
Affected Software
2 affected components
Daylight Studio FuelCMS=1.5.2
TheDayLightStudio Fuel CMS=1.5.2
Event History
Apr 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30459?
The severity of CVE-2026-30459 is categorized as high with a CVSS score of 7.1.
2
How do I fix CVE-2026-30459?
To fix CVE-2026-30459, ensure that password reset tokens are generated securely and validate all incoming links for authenticity.
3
What impact does CVE-2026-30459 have on users?
CVE-2026-30459 allows unauthenticated attackers to obtain password reset tokens, potentially compromising user accounts.
4
Which software is affected by CVE-2026-30459?
CVE-2026-30459 affects Daylight Studio FuelCMS version 1.5.2.
5
What should I do if I am using Daylight Studio FuelCMS?
If using Daylight Studio FuelCMS, upgrade to a patched version as soon as it becomes available to mitigate the risks associated with CVE-2026-30459.