CVE-2026-44392: Medium severity Six Apart Movable Type vulnerability
Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44392?
CVE-2026-44392 is classified as a medium severity vulnerability due to its potential impact on unauthorized actions by users without administrative privileges.
How do I fix CVE-2026-44392?
To fix CVE-2026-44392, ensure that all users have appropriate authorization levels and update to the latest version of Movable Type that includes security patches.
What type of vulnerability is CVE-2026-44392?
CVE-2026-44392 is a missing authorization vulnerability that can lead to unintended update processing when non-administrator users are signed in.
Who is affected by CVE-2026-44392?
CVE-2026-44392 affects users of Movable Type who may inadvertently execute updates without proper authorization.
Is there a workaround for CVE-2026-44392?
While there is no specific workaround for CVE-2026-44392, restricting user access based on authorization levels can help mitigate the risk until a fix is applied.