{"id":"CVE-2008-1099","aliases":["GHSA-jj2f-57jg-5rm6","PYSEC-2026-677"],"title":"MoinMoin Improper Access Control  ","summary":"MoinMoin Improper Access Control  ","severity":"medium","vendor":"moin","product":"moin","ecosystem":"pip","affected":["moin <= 1.5.8"],"published":"2022-05-01","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jj2f-57jg-5rm6","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1099"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41038"},{"url":"https://usn.ubuntu.com/716-1"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00510.html"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00538.html"},{"url":"http://hg.moinmo.in/moin/1.5/rev/4a7de0173734"},{"url":"http://moinmo.in/SecurityFixes"},{"url":"http://secunia.com/advisories/29262"},{"url":"http://secunia.com/advisories/29444"},{"url":"http://secunia.com/advisories/30031"},{"url":"http://secunia.com/advisories/33755"},{"url":"http://www.debian.org/security/2008/dsa-1514"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200803-27.xml"},{"url":"http://www.securityfocus.com/bid/28177"}],"tags":["osv","pip"],"epss":0.02022,"epssPercentile":0.79841,"ingestedAt":"2026-07-08T18:25:50.807Z","slug":"CVE-2008-1099","body":"## Overview\n\n`_macro_Getval` in `wikimacro.py` in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages. The issue has been fixed on [4a7de0173734](http://hg.moinmo.in/moin/1.5/rev/4a7de0173734).\n\n## Affected packages\n\n- `moin <= 1.5.8`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}