CVE-2026-33088: SQL Injection
Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33088?
CVE-2026-33088 has been classified as a critical severity vulnerability due to its potential to allow arbitrary SQL code execution.
How do I fix CVE-2026-33088?
To fix CVE-2026-33088, you should update to the latest version of Movable Type that addresses this SQL injection vulnerability.
What versions of Movable Type are affected by CVE-2026-33088?
CVE-2026-33088 affects multiple versions of Movable Type, particularly those below 9.1.0, including versions from 8.0.2 to 9.0.7.
What kind of attack can CVE-2026-33088 facilitate?
CVE-2026-33088 can facilitate SQL injection attacks, allowing attackers to execute arbitrary SQL statements against the database.
Is there a workaround for CVE-2026-33088?
There is no established workaround for CVE-2026-33088; updating to a patched version is recommended.