---
id: CVE-2004-0708
aliases:
  - GHSA-7jrp-r6jx-32cw
  - PYSEC-2026-671
title: MoinMoin allows administrative access
summary: MoinMoin allows administrative access
severity: high
vendor: moin
product: moin
ecosystem: pip
affected:
  - moin < 1.2.2
patched:
  - moin 1.2.2
published: '2022-04-29'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7jrp-r6jx-32cw'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2004-0708'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16465'
  - url: 'http://secunia.com/advisories/11807'
  - url: >-
      http://sourceforge.net/tracker/index.php?func=detail&aid=948103&group_id=8482&atid=108482
  - url: 'http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml'
  - url: 'http://www.osvdb.org/6704'
  - url: 'http://www.securityfocus.com/bid/10568'
tags:
  - osv
  - pip
epss: 0.01767
epssPercentile: 0.7677
ingestedAt: '2026-07-08T18:25:47.037Z'
---

## Overview

MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.

## Affected packages

- `moin < 1.2.2`

## Remediation

Upgrade to a patched release:

- `moin 1.2.2`
