CVE-2026-30458Disclosure(thedaylightstudio / fuel_cms)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-620

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fuel_cms

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-29)
  • 3 total mentions across 2 days

Affected systems

Products
fuel_cms

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 1Mentions · 2026-03-29: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 203-2803-29
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-03-292
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30458 An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. https://www.cve.org/CVERecord?id=CVE-2026-30458

    Post summary

    The text announces CVE‑2026‑30458, noting that Daylight Studio FuelCMS v1.5.2 can be exploited to steal password‑reset tokens through mail splitting. No PoC, exploit code, or active exploitation claims are provided.

    00011191
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30458 An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. https://www.cve.org/CVERecord?id=CVE-2026-30458 ----- Traducción: CVE-2026-30458 Un problema en Daylight Studio FuelCMS v… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑30458, describing a mail‑splitting vulnerability that enables exfiltration of password‑reset tokens, but provides no PoC, exploit, or patch information.

    0000028
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30458 - Critical An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. https://www.thehackerwire.com/vulnerability/CVE-2026-30458/ https://t.co/6snunxMER1

    Post summary

    The tweet announces the critical CVE-2026-30458 in Daylight Studio FuelCMS v1.5.2, noting that attackers can exfiltrate password reset tokens using a mail splitting attack, but provides no PoC, exploitation tools, patch details, or evidence of active use.

    0000034
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appthedaylightstudiofuel_cms1.5.2--

Explore more