
CVE-2026-30459 An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a c… https://www.cve.org/CVERecord?id=CVE-2026-30459
Post summary
The note announces CVE-2026-30459, revealing a flaw in FuelCMS's password reset that permits unauthenticated theft of reset tokens, with no mention of a PoC, exploit tool, or patch.

