---
id: CVE-2026-25776
title: Movable Type provided by Six Apart Ltd
summary: >-
  Movable Type provided by Six Apart Ltd. contains a code injection
  vulnerability which may allow an attacker to execute arbitrary Perl script.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: sixapart
product: movable_type
affected:
  - movable_type <= 2.14
  - movable_type = 9.0.5
  - movable_type = 9.0.6
  - movable_type = 9.1.0
  - 'movable_type >= 8.0.2, < 8.0.10'
  - 'movable_type >= 8.8.0, < 8.8.3'
  - 'movable_type >= 9.0.1, < 9.0.7'
patched:
  - movable_type 9.0.7
published: '2026-04-08'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-25776'
references:
  - url: 'https://jvn.jp/en/jp/JVN66473735/'
    label: vultures@jpcert.or.jp
  - url: 'https://movabletype.org/news/2026/04/mt-907-released.html'
    label: vultures@jpcert.or.jp
  - url: 'https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html'
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.00727
epssPercentile: 0.52122
ingestedAt: '2026-07-25T23:05:59.005Z'
---

## Overview

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

## Affected

- `movable_type <= 2.14`
- `movable_type = 9.0.5`
- `movable_type = 9.0.6`
- `movable_type = 9.1.0`
- `movable_type >= 8.0.2, < 8.0.10`
- `movable_type >= 8.8.0, < 8.8.3`
- `movable_type >= 9.0.1, < 9.0.7`

## Remediation

Upgrade past the affected range:

- `movable_type 9.0.7`
