← Vulnerability feed

Vulnerability record · CVE-2021-32648 · published 26 August 2021

CVE-2021-32648: October CMS password reset authentication bypass

Octobercms · October

October CMS, a Laravel-based CMS, contains an improper authentication flaw in the october/system package. An attacker can request an account password reset and then gain access to that account by sending a specially crafted request. Because no authentication or user interaction is required, any reachable instance is exposed.

9.1 CVSS 3.1 Critical CISA KEV since 18 Jan 2022 EPSS 90% · top 0.2% CWE-287 · Improper authentication
9.1CVSS 3.1 base score, v2 6.4
90%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityNetwork-reachable authentication bypass with no prerequisites, a CVSS score of 9.1, KEV listing, and a very high EPSS probability make this an urgent patch target.

What it is

October CMS, a Laravel-based CMS, contains an improper authentication flaw in the october/system package. An attacker can request an account password reset and then gain access to that account by sending a specially crafted request. Because no authentication or user interaction is required, any reachable instance is exposed.

Impact

An attacker gains full access to a targeted user account, including administrative accounts, allowing data theft and modification of site content or configuration. The CVSS vector shows high confidentiality and integrity impact with no availability impact.

Attack surface

Reachable over the network through the password reset functionality; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed.

Exploitation

It is listed in CISA KEV with a due date of 2022-02-01, and EPSS gives a 30-day probability of 0.90418 (99.8th percentile), indicating active exploitation is expected. No public exploit code or ransomware use is documented in this record.

What to do

  • Upgrade the october/system package to Build 472 or v1.1.5, or later, per the vendor advisory.
  • If immediate patching is not possible, restrict or disable the password reset endpoint until the update is applied.
  • Enforce multi-factor authentication on all accounts, especially administrator accounts, to limit the value of a bypassed password reset.
  • Monitor and rate-limit password reset requests from single sources to reduce automated abuse.

Detection

  • Review web server and application logs for password reset requests followed immediately by successful logins from the same source.
  • Alert on password reset requests with unusual or malformed parameters, especially those not matching the expected form fields.
  • Audit account activity for logins from new IP addresses or user agents shortly after a password reset event.
  • Correlate authentication logs with the known KEV listing to prioritize triage of any suspicious reset-then-login sequences.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-32648 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "October CMS Improper Authentication". Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32648 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-3311Octobercms october insufficient session expiration vulnerabilityAn issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occur…EPSS 2.9%9.8CVE-2017-1000194Octobercms october unrestricted file upload vulnerabilityOctober CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly othe…EPSS 1.2%9.8CVE-2017-1000196Octobercms october code injection vulnerabilityOctober CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applicat…EPSS 1.9%9.8CVE-2017-1000197Octobercms october vulnerabilityOctober CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the serve…EPSS 1.2%9.1CVE-2023-44382Octobercms october code injection vulnerabilityOctober is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms…EPSS 0.87%8.8CVE-2021-32649Octobercms october injection vulnerabilityOctober CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…EPSS 1.3%8.8CVE-2021-32650Octobercms october injection vulnerabilityOctober CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…EPSS 2.1%8.8CVE-2017-16941Octobercms october unrestricted file upload vulnerabilityOctober CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by dow…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2021-32648), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.