CVE-2026-24447: Medium severity Movable Type Movable Type 7 vulnerability
If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24447?
CVE-2026-24447 is classified as a medium severity vulnerability due to the potential for arbitrary code execution upon opening a malicious CSV file.
How do I fix CVE-2026-24447?
To fix CVE-2026-24447, update to the latest version of Movable Type 7 or Movable Type 8.4, which includes the necessary security patches.
What is the impact of CVE-2026-24447?
The impact of CVE-2026-24447 is that malicious data may lead to code execution in a user's environment when they open a compromised CSV file.
Which versions of Movable Type are affected by CVE-2026-24447?
CVE-2026-24447 affects Movable Type 7 series and Movable Type 8.4.
Who is at risk from CVE-2026-24447?
Users of Movable Type 7 and 8.4 who download and open CSV files containing malformed data are at risk from CVE-2026-24447.