[Japanese]

JVNDB-2026-000146

Multiple vulnerabilities in Movable Type

Overview

Movable Type provided by Six Apart Ltd. contains multiple vulnerabilities listed below:
  • Code Injection in the Upgrade Script (CWE-94) - CVE-2026-96408
  • SQL Injection in the Site Search function (CWE-89) - CVE-2026-103668

In addition, multiple vulnerabilities have been addressed. For details, refer to the information provided by the developer.

RyotaK of GMO Flatt Security Inc. reported these vulnerabilities to the developer and coordinated. After the coordination was completed, the developer reported the case to JPCERT/CC to notify users of the solution through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 9.4 (Critical) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: Low
CVSS v4 Severity
Base Metrics: 9.3 (Critical) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): Low
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-96408


CVSS v3 Severity
Base Metrics: 8.6(High) [IPA Score]
  • Access Vector : Network
  • Attack Complexity : Low
  • Privileges Required : None
  • User Interaction : None
  • Scope : Unchanged
  • Confidentiality Impact : High
  • Integrity Impact : Low
  • Availability Impact : Low
CVSS v4 Severity
Base Metrics: 8.8 (High) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): Low
  • Availability Impact (VA): Low
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-103668
Affected Products


Six Apart, Ltd.
  • Movable Type 9.2.1 and earlier (9.2.x series, Cloud Edition only)
  • Movable Type 9.0.9 and earlier (9.0.x series, including Advanced Edition)
  • Movable Type 8.8.5 and earlier (8.8.x series, including Advanced Edition)
  • Movable Type 8.0.12 and earlier (8.0.x series, including Advanced Edition)
  • Movable Type Premium 9.2.1 and earlier (9.2.x series, Cloud Edition only)
  • Movable Type Premium 9.0.9 and earlier (9.0.x series, including Advanced Edition)
  • Movable Type Premium 2.17 and earlier (2.x series, including Advanced Edition)

Note that EOL products including Movable Type 8.4.x series, 7.x series and earlier versions, and Movable Type Premium 1.x series are affected.
Impact

  • Arbitrary Perl script or SQL query execution on the affected product (CVE-2026-96408).
  • Arbitrary SQL query execution on the affected product (CVE-2026-103668).
Solution

[Update the Software]
Update the affected product to the latest version according to the information provided by the developer.
The following versions have been released to address these vulnerabilities:
  • Movable Type (including Advanced Edition)
    • 9.3.0
    • 9.0.10
    • 8.8.6
    • 8.0.13
  • Movable Type Premium (including Advanced Edition)
    • 9.3.0
    • 9.0.10
    • 2.18
[Apply workaround]
If updating the product is not feasible, users can mitigate the impact of these vulnerabilities by taking the following actions:
  • Delete the mt-upgrade.cgi, mt-search.cgi files, and mt-ftsearch.cgi, or remove execute permissions from them (CGI).
  • Add RestrictedPSGIApp upgrade, RestrictedPSGIApp new_search, and RestrictedPSGIApp ft_search settings to mt-config.cgi (PSGI, MT 6.2 and later; MT 6.2.4 and later for RestrictedPSGIApp ft_search).
For details, refer to the information provided by the developer.
Vendor Information

Six Apart, Ltd.
CWE (What is CWE?)

  1. SQL Injection(CWE-89) [IPA Evaluation]
  2. Code Injection(CWE-94) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-96408
  2. CVE-2026-103668
References

  1. JVN : JVN#91153973
Revision History

  • [2026/10/07]
      Web page was published