Vulnerability record · CVE-2021-20837 · published 26 October 2021
CVE-2021-20837: Movable Type XMLRPC API OS command injection
SSixapart · Movable Type
Movable Type 7, 6, Advanced and Premium editions (and all versions 4.0 or later, including EOL releases) contain an OS command injection flaw reachable through unspecified vectors, with public reporting pointing at the XMLRPC API. Successful exploitation lets a remote, unauthenticated attacker run arbitrary operating system commands on the server, which is severe for a widely deployed publishing platform.
Description
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and very high EPSS plus public exploit references make this an urgent patch target.
What it is
Movable Type 7, 6, Advanced and Premium editions (and all versions 4.0 or later, including EOL releases) contain an OS command injection flaw reachable through unspecified vectors, with public reporting pointing at the XMLRPC API. Successful exploitation lets a remote, unauthenticated attacker run arbitrary operating system commands on the server, which is severe for a widely deployed publishing platform.
Impact
An attacker gains arbitrary OS command execution on the host running Movable Type, enabling full compromise of the application and its data, and potentially the underlying server.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), and public exploit write-ups reference the XMLRPC API, so the vulnerable endpoint is directly reachable over HTTP. No authentication is required per the vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.88144, 99.76th percentile) and public exploit references exist on Packet Storm, indicating active interest and readily available exploit material.
What to do
- Upgrade to the fixed Movable Type releases referenced in the vendor advisory (MT 7.8.2 / 6.8.3 and corresponding Advanced/Premium builds).
- If immediate patching is not possible, restrict or block access to the XMLRPC API endpoint at the web server or WAF.
- Retire or isolate unsupported/EOL Movable Type versions, which the advisory states remain affected.
- Run the Movable Type service under a low-privilege account with no unnecessary OS permissions.
- Monitor vendor and JVN advisories for updated guidance.
Detection
- Inspect web server and application logs for POST requests to XMLRPC endpoints with suspicious or shell-like payload content.
- Alert on unexpected child processes spawned by the web server or application user (e.g., shell, curl, wget).
- Monitor for outbound network connections originating from the Movable Type host to unfamiliar destinations.
- Review file integrity on the Movable Type installation and web root for newly written files or modified scripts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164705/Movable-Type-7-r.5002-XMLRPC-API-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/164818/Movable-Type-7-r.5002-XMLRPC-API-Remote-Command-Injection.html | Third Party AdvisoryVDB Entry |
| https://jvn.jp/en/jp/JVN41119755/index.html | Third Party Advisory |
| https://movabletype.org/news/2021/10/mt-782-683-released.html | Release NotesVendor Advisory |
| http://packetstormsecurity.com/files/164705/Movable-Type-7-r.5002-XMLRPC-API-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/164818/Movable-Type-7-r.5002-XMLRPC-API-Remote-Command-Injection.html | Third Party AdvisoryVDB Entry |
| https://jvn.jp/en/jp/JVN41119755/index.html | Third Party Advisory |
| https://movabletype.org/news/2021/10/mt-782-683-released.html | Release NotesVendor Advisory |
Track CVE-2021-20837 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20837), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.