CVE-2026-44392: Six Apart Ltd Movable Type

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.

Affected products

  • Six Apart Ltd Movable Type: up to and including 9.1.1; up to and including 9.0.7; up to and including 8.8.3; up to and including 8.0.10
  • Six Apart Ltd Movable Type Advanced: up to and including 9.0.7; up to and including 8.8.3; up to and including 8.0.10
  • Six Apart Ltd Movable Type Premium: up to and including 9.1.1; up to and including 9.0.7
  • Six Apart Ltd Movable Type Premium Advanced Edition: up to and including 9.1.1; up to and including 9.0.7

Published 2026-05-20. Last modified 2026-07-24.