---
id: CVE-2004-1463
aliases:
  - GHSA-9xh4-wpx8-rg2w
  - PYSEC-2026-674
title: MoinMoin Improper Privilege Management
summary: MoinMoin Improper Privilege Management
severity: high
vendor: moin
product: moin
ecosystem: pip
affected:
  - moin < 1.2.3
patched:
  - moin 1.2.3
published: '2022-04-29'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-9xh4-wpx8-rg2w'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2004-1463'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16832'
  - url: >-
      http://sourceforge.net/project/shownotes.php?group_id=8482&release_id=254801
  - url: 'http://www.gentoo.org/security/en/glsa/glsa-200408-25.xml'
  - url: 'http://www.osvdb.org/displayvuln.php?osvdb_id=8195'
  - url: 'http://www.securityfocus.com/bid/10801'
tags:
  - osv
  - pip
epss: 0.02283
epssPercentile: 0.82219
ingestedAt: '2026-07-08T18:25:48.122Z'
---

## Overview

MoinMoin 1.2.2 and earlier could allow a remote attacker to gain elevated privileges, caused by an undisclosed Access Control List (ACL) vulnerability in the PageEditor.



## Affected packages

- `moin < 1.2.3`

## Remediation

Upgrade to a patched release:

- `moin 1.2.3`
