CVE-2026-44392: Six Apart Ltd Movable Type
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.
Affected products
- Six Apart Ltd Movable Type: up to and including 9.1.1; up to and including 9.0.7; up to and including 8.8.3; up to and including 8.0.10
- Six Apart Ltd Movable Type Advanced: up to and including 9.0.7; up to and including 8.8.3; up to and including 8.0.10
- Six Apart Ltd Movable Type Premium: up to and including 9.1.1; up to and including 9.0.7
- Six Apart Ltd Movable Type Premium Advanced Edition: up to and including 9.1.1; up to and including 9.0.7
Published 2026-05-20. Last modified 2026-07-24.