Home
MEDIUM: 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NMEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N 9.1.1 and earlier
affected
9.0.7 and earlier
affected
8.8.3 and earlier
affected
8.0.10 and earlier
affected
9.1.1 and earlie
affected
9.0.7 and earlier
affected
8.8.3 and earlier
affected
8.0.10 and earlier
affected
9.1.1 and earlier
affected
9.0.7 and earlier
affected
2.15 and earlier (included in Movable Type 8.8.4 and earlier or Movable Type 8.0.11 and earlier)
affected
9.1.1 and earlier
affected
9.0.7 and earlier
affected
2.15 and earlier (included in Movable Type 8.8.4 and earlier or Movable Type 8.0.11 and earlier)
affected
Description
Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.
Problem types
Product status
References
movabletype.org/news/2026/05/mt-908-released.html
www.sixapart.jp/movabletype/news/2026/05/20-1100.html