CVE-2026-23704: Malicious File Upload
A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23704?
CVE-2026-23704 is considered a high-severity vulnerability due to the potential for arbitrary code execution on the administrator's browser.
How do I fix CVE-2026-23704?
To remediate CVE-2026-23704, update to a version of Movable Type that is not affected, preferably above version 8.4 or apply relevant patches.
Which versions are affected by CVE-2026-23704?
CVE-2026-23704 affects Movable Type versions up to 7.0 and those prior to 8.4, specifically all versions in the 7 series and 8.4 series.
Can non-administrative users exploit CVE-2026-23704?
Yes, a non-administrative user can exploit CVE-2026-23704 by uploading malicious files that may execute scripts when accessed by an administrator.
Is Movable Type 7 series still supported in light of CVE-2026-23704?
No, the Movable Type 7 series is considered End-of-Life (EOL) and is not supported, making it essential to upgrade to a newer version to mitigate CVE-2026-23704.