CVE-2021-32648

HIGH KEV NUCLEI

October CMS < 1.1.5 and System < 1.0.472 - Authentication Bypass via Password Reset

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-32648 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 18, 2022. EIP tracks 2 public exploits. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-32648, an authentication bypass vulnerability in OctoberCMS. The exploit automates the process of resetting the admin password by bypassing token validation, allowing an attacker to gain administrative access.

Description

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

Exploits (2)

vulncheck_xdb WORKING POC
remote
https://github.com/Immersive-Labs-Sec/CVE-2021-32648

This repository contains a functional exploit for CVE-2021-32648, an authentication bypass vulnerability in OctoberCMS. The exploit automates the process of resetting the admin password by bypassing token validation, allowing an attacker to gain administrative access.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: OctoberCMS
No auth needed
Prerequisites: Target OctoberCMS instance · Network access to the target
devstral-2 · analyzed Feb 25, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/immersive-labs-sec/cve-2021-32648

The repository contains a functional exploit for CVE-2021-32648, an authentication bypass vulnerability in OctoberCMS. The exploit automates the process of resetting the admin password by bypassing token validation, allowing an attacker to gain administrative access.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: OctoberCMS
No auth needed
Prerequisites: Target host URL · Network access to the target
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Nuclei Templates (1)

OctoberCMS - Account Takeover
HIGHVERIFIEDby daffainfo
Shodan: http.component:"october cms"

Scores

CVSS v3 8.2
EPSS 0.9304
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2022-01-18
VulnCheck KEV 2022-01-18
InTheWild.io 2022-01-14
ENISA EUVD EUVD-2021-1808
CWE
CWE-287
Status published
Products (3)
october/system 0 - 1.0.472Packagist
octobercms/october 1.0.471
octobercms/october 1.1.1 - 1.1.5
Published Aug 26, 2021
KEV Added Jan 18, 2022
Tracked Since Feb 18, 2026