CVE-2026-33088Disclosure(sixapart / movable_type)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sixapart movable_type systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • movable_type

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-08); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
movable_type

3 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-08: 1Mentions · 2026-04-11: 1Mentions · 2026-04-12: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-15: 104-0804-1104-1204-15
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-081
Patch1
2026-04-111
Disclosure1
2026-04-121
Disclosure1
2026-04-151
Disclosure1
Full discourse4 posts
  • Mr.Rabbit@01ra66it
    Disclosure

    【Movable Typeにおける複数の脆弱性】 JVNが公表した Movable Type の脆弱性は、4月15日時点でもかなり重い継続監視案件です。CVE-2026-25776 はコードインジェクション、CVE-2026-33088 は SQL インジェクションで、現行版だけでなく EOL 版まで広く影響します。日本では自治体、学校、企業の対外サイトで長期運用されているケースが多く、更新停滞環境を狙われやすい構図です。 特に厄介なのは、管理画面や Data API を含む運用面で刺さることです。表に出るトップページだけ見て安心していると、裏側の管理機能が穴になる。古い版では修正版が出ないため、運用停止・制限・更改を含めた判断が必要になります。 防御側は、Movable Type の有無、版数、Data API 利用有無、委託先保守の状態を即時確認したいところです。すぐ更新できない環境は、少なくとも回避策と公開面の絞り込みを先に進めるべきです。 #MovableType #JVN #RCE #SQLi #CMS #脆弱性対策 #WebSecurity https://jvn.jp/jp/JVN66473735/index.html

    Post summary

    The post announces two critical CVEs (code injection and SQL injection) in Movable Type across all versions, urging immediate assessment and mitigation, but provides no PoC, exploit code, active usage evidence, or patch details.

    00012282
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33088 Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. https://www.cve.org/CVERecord?id=CVE-2026-33088

    Post summary

    CVE-2026-33088 is an SQL injection flaw in Movable Type that could allow attackers to run arbitrary SQL commands. No PoC, exploit code, patch, or active exploitation details are mentioned.

    00000224
    57.1K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【Movable Typeにおける複数の脆弱性】 JVNは、Movable TypeにRCE相当のコードインジェクション(CVE-2026-25776、CVSS v3 9.8)とSQLインジェクション(CVE-2026-33088、CVSS v3 7.3)があると公表しました。影響範囲が広く、サポート中の版だけでなくEOL済みの旧版にも及びます。 日本では企業サイト、団体サイト、制作会社管理のWebにMovable Typeが残りやすく、しかも“中の人が版数を把握していない”ケースが少なくありません。そのため、この脆弱性は単なるCMS更新ではなく、公開資産台帳の不備そのものを突いてくる可能性があります。 想定されるのは、公開Web経由の初期侵入、改ざん、DB操作、管理権限奪取、そこから先の横展開です。影響が長寿命の旧版に広がるので、保守契約が切れているサイトほど危険度が上がります。 日本側でまず見るべきは、Movable Typeの存在有無、版数、Data APIの有効化、保守委託先、そしてWAFやアクセスログの異常です。 #MovableType #JVN #CVE202625776 #CVE202633088 #脆弱性対策 https://jvn.jp/jp/JVN66473735/

    Post summary

    JVN has disclosed two critical vulnerabilities in Movable Type—a code injection (CVE‑2026-25776) and a SQL injection (CVE‑2026-33088)—with high CVSS scores, emphasizing significant risk especially for obsolete versions.

    00000243
    3.5K followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Movable Type — Code Injection (CVE-2026-25776) and SQL Injection (CVE-2026-33088) 📅 **Timeline:** Disclosure: 2026-04-08 🆔 **CVE-2026-25776** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: Not Available% 🆔 **CVE-2026-33088** | 📊 CVSS: 5.3 (Medium 🟡) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Movable Type/Advanced/Premium: 9.1.0 and earlier, 9.0.6 and earlier, 8.8.2 and earlier, 8.0.9 and earlier, End-of-support releases (MT 5–7, MT8.4.x, Premium 1.x) 🔧 **Fixed Versions:** Movable Type 9.1.1 (cloud), 9.0.7, 8.8.3, 8.0.10, Movable Type Premium / MT8 base: 9.1.1 / 2.15 🫨 **Attack Vectors:** - Network (remote) - Unauthenticated attacker - Exposed Data API endpoints - Listing framework (administrative endpoints) 📝 **Summary:** CVE-2026-25776 is a critical code-injection vulnerability allowing unauthenticated remote execution of arbitrary Perl code via the listing-framework or Data API, enabling full system compromise. CVE-2026-33088 is a SQL injection vulnerability allowing unauthenticated SQL execution leading to data disclosure/modification; both stem from insufficient input validation in exposed admin/API components. 📈 **Impact Scope:** Unauthenticated remote RCE (CVE-2026-25776) and unauthenticated SQL execution/data compromise (CVE-2026-33088). Potential for full system compromise depending on deployment, privileges, and exposed interfaces. 🛡️ **Recommended Actions:** - Apply vendor patches immediately to affected installations (see fixed versions). - If patching is not possible, disable or restrict Data API and listing-framework endpoints and remove public exposure. 🪢 **Related Resources:** - https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html - https://jvn.jp/jp/JVN66473735/ 🏷 **Tags:** #Cybersecurity #MovableType #RCE

    Post summary

    This post discloses critical code‑injection and medium SQL‑injection CVEs in Movable Type, detailing RCE and data‑compromise risks, and recommends applying vendor patches immediately.

    0000057
    276 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appsixapartmovable_type---
Appsixapartmovable_type---
Appsixapartmovable_type9.0.5--
Appsixapartmovable_type9.0.6--
Appsixapartmovable_type9.1.0--
Appsixapartmovable_type9.1.0--

Explore more