Junglewise Threat Intelligence

CVE-2026-44392: Six Apart Movable Type missing authorization in upgrade process

CVE-2026-44392 · Severity: medium · CVSS 4.3 · Published 2026-05-20

Technologies: Six Apart Ltd. Movable Type Premium. Vendors: Six Apart Ltd..

Executive brief

Movable Type, a popular content management system, contains a security flaw that allows users with low-level access to perform administrative update tasks. Specifically, when the software or its plugins require an update, a user without administrator privileges can trigger the upgrade process. This could lead to unauthorized changes to the system configuration or unintended service modifications.

Technical details

A missing authorization vulnerability (CWE-862) exists in Movable Type and Movable Type Premium. The flaw resides in the upgrade logic; when the core product or installed plugins are pending an upgrade, the system fails to properly verify administrative privileges before allowing a signed-in user to initiate the update processing. An authenticated attacker with low-level (non-admin) privileges can exploit this to execute unintended update tasks. The vendor has addressed this by introducing the 'RequireUpgradePermission' environment variable to enforce proper authorization checks. Patches are available in versions 9.2.0, 9.0.8, 8.8.4, and 8.0.11.

Affected products

  • Six Apart Ltd. Movable Type 9.1.0 and earlier, 9.0.6 and earlier, 8.8.2 and earlier, 8.0.9 and earlier, 7 series, 6 series, 5 series
  • Six Apart Ltd. Movable Type Premium 9.1.0 and earlier, 9.0.6 and earlier, 2.14 and earlier, 1.0 to 1.68

Timeline

  • 2026-05-20: disclosed: Vulnerability disclosed by JPCERT/CC and Six Apart Ltd.
  • 2026-05-20: patched: Fixed versions 9.2.0, 9.0.8, 8.8.4, and 8.0.11 released.

References

Related threats