PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103668 Six Apart Ltd. CVE debrief

An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product. This vulnerability has a high severity with a CVSS score of 8.6. Defenders should prioritize verifying exposure, assessing potential impact, and remediating vulnerable installations to prevent unauthorized database access and data tampering. The vulnerability is confirmed in Movable Type's Site Search function, and defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Vendor
Six Apart Ltd.
Product
Movable Type Cloud Edition
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Movable Type installations, particularly those using the Site Search function, should assess exposure and prioritize verification and remediation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review the vulnerability and take appropriate actions to protect their systems.

Why it matters

CVE-2026-103668 is a high-severity SQL Injection vulnerability in Movable Type's Site Search function. Defenders should prioritize verifying exposure, assessing potential impact, and remediating vulnerable installations to prevent unauthorized database access and data tampering.

  • Potential unauthorized database access
  • Possible data tampering or extraction
  • Required verification of Movable Type version and configuration
  • Necessity for enhanced database security measures

Technical summary

The CVE record describes an SQL Injection vulnerability in Movable Type's Site Search function. The vulnerability may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product. This vulnerability has a high severity with a CVSS score of 8.6. Defenders should prioritize verifying exposure, assessing potential impact, and remediating vulnerable installations to prevent unauthorized database access and data tampering. The vulnerability is confirmed in Movable Type's Site Search function.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, focusing on Site Search function usage and database security.

Recommended defensive actions

  • Verify Movable Type version and Site Search function usage
  • Assess database security and access controls
  • Review and update Movable Type to patched version 9.2.1 or later
  • Monitor for suspicious database queries
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the SQL Injection vulnerability in Movable Type's Site Search function. Vendor advisories offer additional context. The vulnerability has a CVSS score of 8.6 and is considered high-severity. Defenders should verify exposure, assess potential impact, and remediate vulnerable installations. The CVE record was published on 2026-10-07T10:19:10.413Z and has not been modified since then. The NVD entry and vendor advisories provide further information on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103668 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103668

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103668 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103668

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-103668

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103668.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://movabletype.org/news/2026/10/mt-930-released.html

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.sixapart.jp/movabletype/news/2026/10/07-1100.html

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://jvn.jp/en/jp/JVN91153973/

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.