Impact Scope and Mitigation Policy for Multiple Vulnerabilities in Movable Type (JVN#91153973)

セキュリティカテゴリを表すパンダのイラスト Security

About This Article
This article was generated using an automated workflow leveraging generative AI. Although organized based on reference information, the author has not performed verification on physical or test hardware.

Verification Status: unverified (hardware not verified)

A severe vulnerability has been disclosed in the content management system "Movable Type," provided by Six Apart, Ltd., which may allow arbitrary Perl code or SQL commands to be executed. Affected environments require prompt updates to the latest version provided by the vendor, or the application of workarounds such as temporary access restrictions or feature disabling.

Key Points of Vulnerabilities Disclosed in JVN#91153973

According to the security advisory from the Information-technology Promotion Agency, Japan (IPA), code injection and SQL injection vulnerabilities exist in the content management system "Movable Type."

If these vulnerabilities are exploited, third parties could potentially execute arbitrary Perl code on the system or run arbitrary SQL commands against the database. Because this may lead to website defamation, leakage of confidential information, and unauthorized manipulation of the server itself, identifying the usage environment early and taking action is essential.

Additionally, primary sources note that multiple other vulnerabilities are addressed and fixed alongside the above, and a detailed review is recommended to ensure comprehensive security.

Affected Products and Version Conditions

The products and versions listed as targets in the published advisory are extensive. Because the applicable conditions vary by edition and version series in operation, accurate identification is critical. The target products listed in the primary source are as follows.

  • Movable Type 9.2 series (Cloud edition only):Movable Type 9.2.1 and earlier

  • Movable Type 9.0 series (including Advanced):Movable Type 9.0.9 and earlier

  • Movable Type 8.8 series (including Advanced):Movable Type 8.8.5 and earlier

  • Movable Type 8.0 series (including Advanced):Movable Type 8.0.12 and earlier

  • Movable Type Premium 9.2 series (Cloud edition only):Movable Type Premium 9.2.1 and earlier

  • Movable Type Premium 9.0 series (including Advanced):Movable Type Premium 9.0.9 and earlier

  • Movable Type Premium 2 series (including Advanced):Movable Type Premium 2.17 and earlier

As an additional point of note, the primary source states that Movable Type 8.4 series, 7 series, and earlier versions, as well as the Movable Type Premium 1 series, which have already reached end-of-life, are also affected by this vulnerability. Since environments continuing to operate legacy versions are not exempt, an inventory of the entire system is essential.

Severity and Attack Risk Based on CVSS v3

The severity of this vulnerability is assessed based on the Common Vulnerability Scoring System (CVSS v3). The identifiers and base scores indicated in the primary source are as follows:

CVE IdentifierCVSS v3 SeverityCVSS v3 Base Score
CVE-2026-96408Critical9.4
CVE-2026-103668High8.6

CVE-2026-96408 has a very high base score of 9.4 and is classified as Critical in severity. This score implies risks such as remote code execution, and the business impact in the event of an attack is catastrophic. Additionally, CVE-2026-103668 is rated as High with a base score of 8.6, and prompt countermeasures against both vulnerabilities are strongly required.

Structuring the Mitigation Workflow and Application Decisions

To grasp the overall picture of the response procedures in the operating environment, the decision branching from version verification to mitigation application is organized into the following workflow.

flowchart TD
    Start[Movable Type環境の確認] --> CheckVer{対象バージョンに該当するか}
    CheckVer -- 該当しない --> Safe[対策不要 / 継続運用]
    CheckVer -- 該当する --> CanUpdate{最新版への即時アップデートが可能か}
    CanUpdate -- 可能 --> ApplyUpdate[修正済みバージョンへアップデート]
    CanUpdate -- 困難 --> SelectEnv{実行環境の種別}
    SelectEnv -- CGI環境 --> WorkaroundCGI[CGIファイルの削除または実行権限削除]
    SelectEnv -- PSGI環境 --> WorkaroundPSGI[mt-config.cgiに制限設定を追加]
    WorkaroundCGI --> PlanUpdate[後日のアップデート計画を策定]
    WorkaroundPSGI --> PlanUpdate

As shown in this workflow, it is first determined whether the running edition and version meet the target criteria. If they match, the system evaluates whether an update to the patched version is feasible, and if an immediate update is difficult, workarounds according to the operational mode (CGI or PSGI) are applied.

Update procedures and version compatibility based on official information

The definitive solution is to update to the latest patched version provided by the developer. Official sources recommend migrating to the following fixed versions.

  • Movable Type Standard / Advanced:9.3.0, 9.0.10, 8.8.6, 8.0.13

  • Movable Type Premium:9.3.0, 9.0.10, 2.18

When performing an update, select the patched version corresponding to the series currently in use. For example, the standard approach is to apply the latest version within the same series: upgrade to 8.8.6 if operating the 8.8 series, or to 8.0.13 if operating the 8.0 series.

Furthermore, if you are using an older version whose support has ended (such as the 8.4 series or version 7 and earlier), upgrading to the latest supported series becomes a consideration.

Workarounds and precautions when updates are difficult

If product updates cannot be performed immediately due to operational constraints or the time required to verify system compatibility, official information provides workarounds to mitigate the impact. The following methods are suggested depending on the operational mode.

1. Countermeasures in a CGI environment

In environments running as CGI, block the attack vector by disabling access to specific files.

  • Target file:mt-upgrade.cgi、mt-search.cgi、mt-ftsearch.cgi

  • Action: Delete the target file or remove the execution permissions for the target file.

2. Countermeasures in a PSGI environment

When operating in a PSGI environment (MT 6.2 or later), add restriction directives to the configuration file mt-config.cgi.

  • Configuration line to add:

    • RestrictedPSGIApp upgrade

    • RestrictedPSGIApp new_search

    • RestrictedPSGIApp ft_search(※RestrictedPSGIApp ft_search (The description applies to MT 6.2.4 and later)

Implementing these workarounds may disable the affected search and upgrade-related functions, so it is important to apply them after considering their operational impact. Furthermore, since these are only provisional mitigation measures, applying the official update eventually is strongly recommended.

Conducting Asset Inventories and Safe Verification in Practice

To handle security responses safely, it is necessary to avoid testing that mimics exploit code or performs dangerous operations, and instead conduct non-destructive inventories by reading configuration information.

In environments hosting Movable Type on Windows servers, when investigating the presence of configuration files and related scripts, PowerShell read-only commands can be used to assess the situation.

# 保存名: Check-MTAssets.ps1


# 実行前提: 管理者権限を持つPowerShell端末で実行し、Movable Typeのインストールパスを指定する


# 期待できる確認内容: 対象CGIファイルの有無および読み取り権限状況の確認(実機確認前)

param (
    [string]$MtPath = "C:\inetpub\wwwroot\mt"
)

$targetFiles = @("mt-upgrade.cgi", "mt-search.cgi", "mt-ftsearch.cgi")

foreach ($file in $targetFiles) {
    $fullPath = Join-Path -Path $MtPath -ChildPath $file
    if (Test-Path -Path $fullPath) {
        $item = Get-Item -Path $fullPath
        [PSCustomObject]@{
            FileName     = $file
            Exists       = $true
            Length       = $item.Length
            LastWrite    = $item.LastWriteTime
        }
    } else {
        [PSCustomObject]@{
            FileName     = $file
            Exists       = $false
            Length       = $null
            LastWrite    = $null
        }
    }
}

[Before Actual Device Verification]
By using scripts like the one above, you can organize the presence or absence of workaround target files without stopping or changing the production environment's behavior. In practice, creating a determination checklist by cross-referencing version descriptions in configuration files and system information from the management console is the safest approach.

Conclusion

The key points and constraints to check in advance regarding this vulnerability are as follows.

  • Broad Target Versions: Primary sources state that not only versions 9.2, 9.0, 8.8, and 8.0, but also end-of-life versions such as 8.4, versions 7 and earlier, and various Premium editions are affected.

  • High Risk Assessment: The CVSS v3 base score is up to 9.4 (Critical), presenting risks of arbitrary code execution and SQL command execution.

  • Priority of Permanent Countermeasures: Updating to the patched versions released for each series (such as 9.3.0, 9.0.10, 8.8.6, and 8.0.13) is the best countermeasure.

  • Scope of Workaround Application: If updates cannot be applied immediately, mitigation measures are provided, such as deleting the three related files or removing execution permissions in CGI environments, and in PSGI environments,mt-config.cgi addingRestrictedPSGIApp settings to. Note that functional limitations will occur.

  • Enforcement of Safe Verification Procedures: Even in staging environments, avoid verifications that involve sending malicious input, and it is recommended to determine applicability through static inventories of version information and deployed files.

Reference Information

  • Regarding multiple vulnerabilities in "Movable Type" (JVN#91153973): https://www.ipa.go.jp/security/security-alert/2026/20261007-jvn.html

Document information

Article title
Impact Scope and Mitigation Policy for Multiple Vulnerabilities in Movable Type (JVN#91153973)
Published
Updated
Source
https://papanda925.com/?p=18056&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL