Vulnerability record · CVE-2021-32648 · published 26 August 2021
CVE-2021-32648: October CMS password reset authentication bypass
Octobercms · October
October CMS, a Laravel-based CMS, contains an improper authentication flaw in the october/system package. An attacker can request an account password reset and then gain access to that account by sending a specially crafted request. Because no authentication or user interaction is required, any reachable instance is exposed.
Description
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityNetwork-reachable authentication bypass with no prerequisites, a CVSS score of 9.1, KEV listing, and a very high EPSS probability make this an urgent patch target.
What it is
October CMS, a Laravel-based CMS, contains an improper authentication flaw in the october/system package. An attacker can request an account password reset and then gain access to that account by sending a specially crafted request. Because no authentication or user interaction is required, any reachable instance is exposed.
Impact
An attacker gains full access to a targeted user account, including administrative accounts, allowing data theft and modification of site content or configuration. The CVSS vector shows high confidentiality and integrity impact with no availability impact.
Attack surface
Reachable over the network through the password reset functionality; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed.
Exploitation
It is listed in CISA KEV with a due date of 2022-02-01, and EPSS gives a 30-day probability of 0.90418 (99.8th percentile), indicating active exploitation is expected. No public exploit code or ransomware use is documented in this record.
What to do
- Upgrade the october/system package to Build 472 or v1.1.5, or later, per the vendor advisory.
- If immediate patching is not possible, restrict or disable the password reset endpoint until the update is applied.
- Enforce multi-factor authentication on all accounts, especially administrator accounts, to limit the value of a bypassed password reset.
- Monitor and rate-limit password reset requests from single sources to reduce automated abuse.
Detection
- Review web server and application logs for password reset requests followed immediately by successful logins from the same source.
- Alert on password reset requests with unusual or malformed parameters, especially those not matching the expected form fields.
- Audit account activity for logins from new IP addresses or user agents shortly after a password reset event.
- Correlate authentication logs with the known KEV listing to prioritize triage of any suspicious reset-then-login sequences.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-32648 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "October CMS Improper Authentication". Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-32648 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32648), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.