LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-32648: October CMS Improper Authentication

RBRecent Breaches Vulnerability Intelligence·Jan 18, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 1, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-32648 to its Known Exploited Vulnerabilities catalog on Jan 18, 2022, with a federal patch deadline of Feb 1, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

CVE-2021-32648 is an improper authentication weakness in October CMS (the october/system package). In affected versions, an attacker can request an account password reset and then gain access to the account with a specially crafted request. For IT and security teams running October CMS, this matters because successful abuse can hand an attacker control of a legitimate account without knowing the original password, which can lead to further compromise of the CMS and any data or functionality it protects. Confirm exact affected releases and fixed packages against the vendor advisory.

How it works

This issue falls under CWE-287 (Improper Authentication). Authentication checks that should ensure only a legitimate user completing a password-reset flow can take over the account are insufficient. According to the public summary, an attacker who can trigger a password-reset request for a target account can then use a specially crafted request to gain access to that account. The flaw is in the handling of the reset process rather than in a separate remote code execution primitive. Exact request format, required preconditions, and any session or token details are not expanded here; treat the CISA description as the authoritative high-level behavior and verify mechanics and scope in the vendor advisory before modeling attacks in your environment.

Am I affected? How to find it in your systems

October CMS is a PHP-based content management system commonly deployed as a web application on LAMP/LEMP stacks, cloud app platforms, or internal content portals. Inventory any hosts, containers, or PaaS apps that serve October CMS front ends or admin panels.

If you cannot determine the package version, treat the instance as potentially affected until you confirm otherwise with the vendor guidance.

How to remediate

Patch first. Apply the updates published by the vendor for the october/system package (and any related October CMS components) exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update is applied, reduce exposure with compensating controls appropriate to an improper-authentication / account-takeover weakness in a web CMS.

These steps lower risk but do not replace the patch. Track the vendor advisory and apply the update as soon as operationally possible.

If your data may have been exposed

Actively exploited authentication flaws can lead to account takeover and subsequent data exposure or further compromise of the CMS. Known ransomware use is not documented for this CVE; still treat any confirmed abuse as a potential incident. If you suspect accounts were accessed, follow your incident-response process: isolate affected systems, preserve logs, reset credentials, and assess what data the compromised accounts could reach. You can run a free exposure scan of your email addresses against known breach data to see whether those identities appear in public breach corpora and prioritize further monitoring or credential changes accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOctober CMS · October CMS
WeaknessCWE-287
Added to CISA KEVJan 18, 2022
Federal patch deadlineFeb 1, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities