CVE-2026-30461: Command Injection
Published Apr 15, 2026
·Updated
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function addgitsubmodule.
Affected Software
2 affected components
Daylight Studio FuelCMS=1.5.2
TheDayLightStudio Fuel CMS=1.5.2
Event History
Apr 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30461?
The severity of CVE-2026-30461 is rated high with a CVSS score of 8.3.
2
How do I fix CVE-2026-30461?
To fix CVE-2026-30461, update to the latest version of Daylight Studio FuelCMS that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-30461?
CVE-2026-30461 is an authenticated remote code execution (RCE) vulnerability.
4
What components are affected by CVE-2026-30461?
CVE-2026-30461 affects the /controllers/Installer.php file in Daylight Studio FuelCMS v1.5.2.
5
What is the impact of CVE-2026-30461?
CVE-2026-30461 allows attackers to execute arbitrary code on the affected server, potentially compromising its security.