« Volver al listado

CVE-2026-33088

Estado: AnalizadaMedia (6.9)—

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-33088",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-33088",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-08T13:31:00.450725Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.9,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "9.1.0 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "9.0.6 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "8.8.2 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "8.0.9 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Advanced",
          "versions": [
            {
              "status": "affected",
              "version": "9.1.0 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Advanced",
          "versions": [
            {
              "status": "affected",
              "version": "9.0.6 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Advanced",
          "versions": [
            {
              "status": "affected",
              "version": "8.8.2 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Advanced",
          "versions": [
            {
              "status": "affected",
              "version": "8.0.9 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Premium",
          "versions": [
            {
              "status": "affected",
              "version": "9.1.0 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Premium",
          "versions": [
            {
              "status": "affected",
              "version": "9.0.6 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Premium Advanced Edition",
          "versions": [
            {
              "status": "affected",
              "version": "9.1.0 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Premium Advanced Edition",
          "versions": [
            {
              "status": "affected",
              "version": "9.0.6 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Premium",
          "versions": [
            {
              "status": "affected",
              "version": "2.14 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Premium Advanced Edition",
          "versions": [
            {
              "status": "affected",
              "version": "2.14 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type Premium (MT8-based)",
          "versions": [
            {
              "status": "affected",
              "version": "2.14 and earlier"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "5.1 to 5.18"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "5.2"
            },
            {
              "status": "affected",
              "version": "5.2.1 to 5.2.13"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "affected",
              "version": "6.0.1 to 6.8.8"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "7 r.4207 to r.5510"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "8.4.0 to 8.4.4"
            }
          ]
        },
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "1.0 to 1.68"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-08T09:16:21.213",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN66473735/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://movabletype.org/news/2026/04/mt-907-released.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vultures@jpcert.or.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement."
    },
    {
      "lang": "es",
      "value": "Movable Type proporcionado por Six Apart Ltd. contiene una vulnerabilidad de inyección SQL que puede permitir a un atacante ejecutar una sentencia SQL arbitraria."
    }
  ],
  "lastModified": "2026-07-24T23:10:00.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9932FC9-6FE6-4D49-B14A-88655FCC3F09",
              "versionEndExcluding": "8.0.10",
              "versionStartIncluding": "8.0.2"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D1EDB69-C876-44CD-872E-B516269013FF",
              "versionEndExcluding": "8.8.3",
              "versionStartIncluding": "8.8.0"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E752A5F-BD39-4024-9791-D1D816F13599",
              "versionEndExcluding": "9.0.7",
              "versionStartIncluding": "9.0.1"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:advanced:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69BA6472-F15D-4B42-A264-04B9C52FAF11"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium_advanced:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09DB1CCF-6A57-4A3F-AA0F-857A73E71792",
              "versionEndIncluding": "2.14"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:9.0.5:*:*:*:premium_advanced:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7212698E-C32C-418D-9674-5A92AF165D58"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:9.0.6:*:*:*:premium_advanced:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19071E2C-D05C-4DD5-85A5-278F99AF152B"
            },
            {
              "criteria": "cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:premium_advanced:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99E9FBCF-3C7A-4383-AEEA-523F091914B1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}