CVE-2026-96408
CVSS Score
9.4
EPSS Score
0.0%
EPSS Percentile
0th
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
| Vendor | six apart ltd. |
| Product | movable type cloud edition |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for six apart ltd. movable type cloud edition
Be the first to know when new critical vulnerabilities affecting six apart ltd. movable type cloud edition are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Affected Versions
Six Apart Ltd. / Movable Type Cloud Edition
9.2.0 ≤ 9.2.1
Six Apart Ltd. / Movable Type
9.0.0 ≤ 9.0.9 8.8.0 ≤ 8.8.5 8.0.0 ≤ 8.0.12
Six Apart Ltd. / Movable Type Premium Cloud Edition
9.2.0 ≤ 9.2.1
Six Apart Ltd. / Movable Type Premium
9.0.0 ≤ 9.0.9 2.0 ≤ 2.17