CVE-2026-96408: Code Injection
Published Oct 7, 2026
·Updated
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
Affected Software
1 affected component
Movable Type Movable Type
Event History
Oct 7, 2026
CVE Published
via MITRE·10:18 AM
Data Sourced
via MITRE·10:18 AM
DescriptionSeverity
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an account or user interaction?
No. The CVSS vector indicates no privileges are required and no user interaction is needed.
2
What level of access does an attacker need?
The issue is remotely exploitable over the network with low attack complexity.
3
What is the potential security impact?
The vulnerability is rated critical with high confidentiality and integrity impact and low availability impact. Successful exploitation may permit arbitrary Perl script execution or SQL query execution.