CVE-2026-96408
Received
Received - Intake
Code Injection in Movable Type Upgrade Script
Vulnerability report for CVE-2026-96408, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-07
Last updated on: 2026-10-07
Assigner: JPCERT/CC
Description
Description
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Six | Apart | Ltd. Movable Type Cloud Edition 9.2.0 |
| Six | Apart | Ltd. Movable Type 9.0.0 |
| Six | Apart | Ltd. Movable Type 8.8.0 |
| Six | Apart | Ltd. Movable Type 8.0.0 |
| Six | Apart | Ltd. Movable Type Premium Cloud Edition 9.2.0 |
| Six | Apart | Ltd. Movable Type Premium 9.0.0 |
| Six | Apart | Ltd. Movable Type Premium 2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-94 | The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. |