Description
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
Published: 2026-10-07
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: SQL Injection that permits execution of arbitrary SQL queries against the database
Action: Patch Immediately
AI Analysis

Impact

An SQL Injection flaw was identified in the Site Search feature of Movable Type, allowing an unauthenticated user to submit crafted input that is incorporated directly into a database query. The flaw can be exploited to run arbitrary SQL statements, potentially leading to full data compromise, unauthorized data retrieval, or subsequent privilege escalation. The weakness corresponds to CWE‑89.

Affected Systems

The affected software includes Six Apart Ltd.’s Movable Type suite, specifically Movable Type, Movable Type Cloud Edition, Movable Type Premium, and Movable Type Premium Cloud Edition. No version information was provided in the CVE data, so all released variants prior to the published fix are potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.8 signals a high severity, ranking this vulnerability as high risk. While no EPSS value is available, the lack of listing in the CISA KEV catalog suggests no widely known exploits are currently distributed. The exploit requires only sending a crafted HTTP request to the search endpoint, and no authentication is required. Consequently, the risk of exposure remains significant for sites that enable Site Search, particularly those exposed to the public internet.

Generated by OpenCVE AI on October 7, 2026 at 11:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Movable Type to the latest release version 9.3.0 or later, as announced in the official release notes; this patch removes the vulnerable code.
  • If an immediate upgrade is not possible, disable or restrict access to the Site Search functionality, ensuring that the endpoint cannot be reached by unauthenticated actors.
  • Implement a web application firewall or input validation rule to reject or sanitize search query parameters that could form part of a SQL statement, thereby limiting the ability of an attacker to inject code.

Generated by OpenCVE AI on October 7, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated SQL Injection in Site Search of Movable Type

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
Weaknesses CWE-89
References
Metrics cvssV3_0

{'score': 8.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-10-07T10:19:10.413Z

Reserved: 2026-10-02T04:23:47.663Z

Link: CVE-2026-103668

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T11:17:09.357

Modified: 2026-10-07T11:17:09.357

Link: CVE-2026-103668

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T11:30:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')