【Movable Typeにおける複数の脆弱性】
JVNが公表した Movable Type の脆弱性は、4月15日時点でもかなり重い継続監視案件です。CVE-2026-25776 はコードインジェクション、CVE-2026-33088 は SQL インジェクションで、現行版だけでなく EOL 版まで広く影響します。日本では自治体、学校、企業の対外サイトで長期運用されているケースが多く、更新停滞環境を狙われやすい構図です。
特に厄介なのは、管理画面や Data API を含む運用面で刺さることです。表に出るトップページだけ見て安心していると、裏側の管理機能が穴になる。古い版では修正版が出ないため、運用停止・制限・更改を含めた判断が必要になります。
防御側は、Movable Type の有無、版数、Data API 利用有無、委託先保守の状態を即時確認したいところです。すぐ更新できない環境は、少なくとも回避策と公開面の絞り込みを先に進めるべきです。
#MovableType#JVN#RCE#SQLi#CMS #脆弱性対策 #WebSecurity
https://jvn.jp/jp/JVN66473735/index.html
Post summary
The post announces two critical CVEs (code injection and SQL injection) in Movable Type across all versions, urging immediate assessment and mitigation, but provides no PoC, exploit code, active usage evidence, or patch details.
CVE-2026-33088 Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. https://www.cve.org/CVERecord?id=CVE-2026-33088
Post summary
CVE-2026-33088 is an SQL injection flaw in Movable Type that could allow attackers to run arbitrary SQL commands. No PoC, exploit code, patch, or active exploitation details are mentioned.
JVN has disclosed two critical vulnerabilities in Movable Type—a code injection (CVE‑2026-25776) and a SQL injection (CVE‑2026-33088)—with high CVSS scores, emphasizing significant risk especially for obsolete versions.
⚠️ **Vulnerability Alert:** Movable Type — Code Injection (CVE-2026-25776) and SQL Injection (CVE-2026-33088)
📅 **Timeline:** Disclosure: 2026-04-08
🆔 **CVE-2026-25776** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: Not Available%
🆔 **CVE-2026-33088** | 📊 CVSS: 5.3 (Medium 🟡) | 📈 EPSS: Not Available%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Movable Type/Advanced/Premium: 9.1.0 and earlier, 9.0.6 and earlier, 8.8.2 and earlier, 8.0.9 and earlier, End-of-support releases (MT 5–7, MT8.4.x, Premium 1.x)
🔧 **Fixed Versions:** Movable Type 9.1.1 (cloud), 9.0.7, 8.8.3, 8.0.10, Movable Type Premium / MT8 base: 9.1.1 / 2.15
🫨 **Attack Vectors:**
- Network (remote)
- Unauthenticated attacker
- Exposed Data API endpoints
- Listing framework (administrative endpoints)
📝 **Summary:**
CVE-2026-25776 is a critical code-injection vulnerability allowing unauthenticated remote execution of arbitrary Perl code via the listing-framework or Data API, enabling full system compromise. CVE-2026-33088 is a SQL injection vulnerability allowing unauthenticated SQL execution leading to data disclosure/modification; both stem from insufficient input validation in exposed admin/API components.
📈 **Impact Scope:** Unauthenticated remote RCE (CVE-2026-25776) and unauthenticated SQL execution/data compromise (CVE-2026-33088). Potential for full system compromise depending on deployment, privileges, and exposed interfaces.
🛡️ **Recommended Actions:**
- Apply vendor patches immediately to affected installations (see fixed versions).
- If patching is not possible, disable or restrict Data API and listing-framework endpoints and remove public exposure.
🪢 **Related Resources:**
- https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html
- https://jvn.jp/jp/JVN66473735/
🏷 **Tags:** #Cybersecurity#MovableType#RCE
Post summary
This post discloses critical code‑injection and medium SQL‑injection CVEs in Movable Type, detailing RCE and data‑compromise risks, and recommends applying vendor patches immediately.