---
id: CVE-2026-103668
title: >-
  An SQL Injection vulnerability exists in the Site Search function of Movable
  Type, which may allow an unauthenticated attacker to execute an arbitrary SQL
  query on the affected product.
summary: >-
  An SQL Injection vulnerability exists in the Site Search function of Movable
  Type, which may allow an unauthenticated attacker to execute an arbitrary SQL
  query on the affected product.
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'
cwe:
  - CWE-89
vendor: Six Apart Ltd.
product: Movable Type Cloud Edition
affected:
  - movable_type_cloud_edition >= 9.2.0 <= 9.2.1
  - movable_type >= 9.0.0 <= 9.0.9
  - movable_type >= 8.8.0 <= 8.8.5
  - movable_type >= 8.0.0 <= 8.0.12
  - movable_type_premium_cloud_edition >= 9.2.0 <= 9.2.1
  - movable_type_premium >= 9.0.0 <= 9.0.9
  - movable_type_premium >= 2.0 <= 2.17
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T11:17:09.357'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103668'
references:
  - url: 'https://jvn.jp/en/jp/JVN91153973/'
    label: vultures@jpcert.or.jp
  - url: 'https://movabletype.org/news/2026/10/mt-930-released.html'
    label: vultures@jpcert.or.jp
  - url: 'https://www.sixapart.jp/movabletype/news/2026/10/07-1100.html'
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T11:26:47.654Z'
---

## Overview

An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
