Daylight Studio FuelCMS Authenticated Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Daylight Studio FuelCMS version 1.5.2, specifically within the Blocks module. This vulnerability arises from improper authorization, allowing authenticated users to execute arbitrary code.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary code on the server where FuelCMS is hosted.

Reproduction

To reproduce this vulnerability, log into a FuelCMS application as any user with valid credentials. Once logged in, access the Blocks module through the preview endpoint. Due to the lack of proper authorization enforcement, any authenticated user can invoke this endpoint, which will result in remote code execution on the server.

Added: Apr 7, 2026, 4:55 PM
Updated: Apr 7, 2026, 4:55 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
10.0
exploitability
6.2
remediation
0.0
relevance
5.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.