---
id: CVE-2004-1462
aliases:
  - GHSA-v744-h36c-hv5j
  - PYSEC-2026-680
title: 'MoinMoin Improper Access Control '
summary: 'MoinMoin Improper Access Control '
severity: high
vendor: moin
product: moin
ecosystem: pip
affected:
  - moin < 1.2.3
patched:
  - moin 1.2.3
published: '2022-04-29'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-v744-h36c-hv5j'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2004-1462'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16833'
  - url: >-
      https://sourceforge.net/project/shownotes.php?group_id=8482&release_id=254801
  - url: 'http://www.gentoo.org/security/en/glsa/glsa-200408-25.xml'
  - url: 'http://www.osvdb.org/displayvuln.php?osvdb_id=8194'
  - url: 'http://www.securityfocus.com/bid/10805'
tags:
  - osv
  - pip
epss: 0.01596
epssPercentile: 0.7424
ingestedAt: '2026-07-08T18:25:53.219Z'
---

## Overview

Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (1) revert and (2) delete.

## Affected packages

- `moin < 1.2.3`

## Remediation

Upgrade to a patched release:

- `moin 1.2.3`
