PT-2026-107475 · Six Apart · Movable Type+3

CVE-2026-96408

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96408

Affected Products

Movable Type
Movable Type Cloud Edition
Movable Type Premium
Movable Type Premium Cloud Edition