Home

Description

Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.

PUBLISHED Reserved 2026-05-18 | Published 2026-05-20 | Updated 2026-05-20 | Assigner jpcert




MEDIUM: 4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

Missing authorization

Product status

9.1.1 and earlier
affected

9.0.7 and earlier
affected

8.8.3 and earlier
affected

8.0.10 and earlier
affected

9.1.1 and earlie
affected

9.0.7 and earlier
affected

8.8.3 and earlier
affected

8.0.10 and earlier
affected

9.1.1 and earlier
affected

9.0.7 and earlier
affected

2.15 and earlier (included in Movable Type 8.8.4 and earlier or Movable Type 8.0.11 and earlier)
affected

9.1.1 and earlier
affected

9.0.7 and earlier
affected

2.15 and earlier (included in Movable Type 8.8.4 and earlier or Movable Type 8.0.11 and earlier)
affected

References

movabletype.org/news/2026/05/mt-908-released.html

www.sixapart.jp/movabletype/news/2026/05/20-1100.html

jvn.jp/en/jp/JVN66473735/

cve.org (CVE-2026-44392)

nvd.nist.gov (CVE-2026-44392)

Download JSON