Published:2026/10/07  Last Updated:2026/10/07

JVN#91153973
Multiple vulnerabilities in Movable Type

Overview

Movable Type provided by Six Apart Ltd. contains multiple vulnerabilities.

Products Affected

  • Movable Type
    • 9.2.1 and earlier (9.2.x series, Cloud Edition only)
    • 9.0.9 and earlier (9.0.x series, including Advanced Edition)
    • 8.8.5 and earlier (8.8.x series, including Advanced Edition)
    • 8.0.12 and earlier (8.0.x series, including Advanced Edition)
  • Movable Type Premium
    • 9.2.1 and earlier (9.2.x series, Cloud Edition only)
    • 9.0.9 and earlier (9.0.x series, including Advanced Edition)
    • 2.17 and earlier (2.x series, including Advanced Edition)
Note that EOL products including Movable Type 8.4.x series, 7.x series and earlier versions, and Movable Type Premium 1.x series are affected.

Description

Movable Type provided by Six Apart Ltd. contains multiple vulnerabilities listed below:

  • Code Injection in the Upgrade Script (CWE-94)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N Base Score 9.3
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Base Score 9.4
    • CVE-2026-96408
  • SQL Injection in the Site Search function (CWE-89)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N Base Score 8.8
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L Base Score 8.6
    • CVE-2026-103668
In addition, multiple vulnerabilities have been addressed. For details, refer to the information provided by the developer.

Impact

  • Arbitrary Perl script or SQL query execution on the affected product (CVE-2026-96408).
  • Arbitrary SQL query execution on the affected product (CVE-2026-103668).

Solution

Update the Software
Update the affected product to the latest version according to the information provided by the developer.
The following versions have been released to address these vulnerabilities:

  • Movable Type (including Advanced Edition)
    • 9.3.0
    • 9.0.10
    • 8.8.6
    • 8.0.13
  • Movable Type Premium (including Advanced Edition)
    • 9.3.0
    • 9.0.10
    • 2.18
Apply workaround
If updating the product is not feasible, users can mitigate the impact of these vulnerabilities by taking the following actions:
  • Delete the mt-upgrade.cgi, mt-search.cgi files, and mt-ftsearch.cgi, or remove execute permissions from them (CGI).
  • Add RestrictedPSGIApp upgrade, RestrictedPSGIApp new_search, and RestrictedPSGIApp ft_search settings to mt-config.cgi (PSGI, MT 6.2 and later; MT 6.2.4 and later for RestrictedPSGIApp ft_search).
For details, refer to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
Six Apart Ltd. Vulnerable 2026/10/07 Six Apart Ltd. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

RyotaK of GMO Flatt Security Inc. reported these vulnerabilities to the developer and coordinated. After the coordination was completed, the developer reported the case to JPCERT/CC to notify users of the solution through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-96408
CVE-2026-103668
JVN iPedia JVNDB-2026-000146