PatchSiren cyber security CVE debrief
CVE-2026-103668 Six Apart Ltd. CVE debrief
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product. This vulnerability has a high severity with a CVSS score of 8.6. Defenders should prioritize verifying exposure, assessing potential impact, and remediating vulnerable installations to prevent unauthorized database access and data tampering. The vulnerability is confirmed in Movable Type's Site Search function, and defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Vendor
- Six Apart Ltd.
- Product
- Movable Type Cloud Edition
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Movable Type installations, particularly those using the Site Search function, should assess exposure and prioritize verification and remediation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review the vulnerability and take appropriate actions to protect their systems.
Why it matters
CVE-2026-103668 is a high-severity SQL Injection vulnerability in Movable Type's Site Search function. Defenders should prioritize verifying exposure, assessing potential impact, and remediating vulnerable installations to prevent unauthorized database access and data tampering.
- Potential unauthorized database access
- Possible data tampering or extraction
- Required verification of Movable Type version and configuration
- Necessity for enhanced database security measures
Technical summary
The CVE record describes an SQL Injection vulnerability in Movable Type's Site Search function. The vulnerability may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product. This vulnerability has a high severity with a CVSS score of 8.6. Defenders should prioritize verifying exposure, assessing potential impact, and remediating vulnerable installations to prevent unauthorized database access and data tampering. The vulnerability is confirmed in Movable Type's Site Search function.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, focusing on Site Search function usage and database security.
Recommended defensive actions
- Verify Movable Type version and Site Search function usage
- Assess database security and access controls
- Review and update Movable Type to patched version 9.2.1 or later
- Monitor for suspicious database queries
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the SQL Injection vulnerability in Movable Type's Site Search function. Vendor advisories offer additional context. The vulnerability has a CVSS score of 8.6 and is considered high-severity. Defenders should verify exposure, assess potential impact, and remediate vulnerable installations. The CVE record was published on 2026-10-07T10:19:10.413Z and has not been modified since then. The NVD entry and vendor advisories provide further information on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103668 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103668
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103668 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103668
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-103668
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103668.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://movabletype.org/news/2026/10/mt-930-released.html
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.sixapart.jp/movabletype/news/2026/10/07-1100.html
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://jvn.jp/en/jp/JVN91153973/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.