Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-29487

24
FAUCET Score

CVE-2021-29487 is an authentication bypass vulnerability affecting frontend users of October CMS, specifically in the october/system package. An unauthenticated attacker can exploit this by sending a specially crafted request, but requires obtaining the Laravel secret key for cookie encryption. This vulnerability has a CVSS score of 7.4 (High) due to its network attack vector and high impact on confidentiality and integrity, despite its high attack complexity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.471, < 1.0.472CPE matchmatch criteria
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
>= 1.1.1, < 1.1.5CPE matchmatch criteria
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.90%
Probability of exploitation in next 30 days
EPSS Percentile
55.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0089 is in the 22nd percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: october/systemFixed in: 1.0.472
composerpatch availablevia ghsa
Product: october/systemFixed in: 1.1.5
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-h76r-vgf3-j6w5high

October CMS auth bypass and account takeover

Aug 30, 2021

References

github.com / octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374
PatchThird Party Advisory
github.com / octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9
PatchThird Party Advisory
github.com / octobercms/october/security/advisories/GHSA-h76r-vgf3-j6w5
PatchThird Party Advisory