---
id: CVE-2007-2637
aliases:
  - GHSA-cmg7-xr2j-4r9v
  - PYSEC-2026-675
title: MoinMoin Improper ACL handling for calendars and includes
summary: MoinMoin Improper ACL handling for calendars and includes
severity: medium
vendor: moin
product: moin
ecosystem: pip
affected:
  - moin < 1.5.8
patched:
  - moin 1.5.8
published: '2022-05-01'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-cmg7-xr2j-4r9v'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2007-2637'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/34474'
  - url: 'https://moinmo.in/MoinMoinRelease1.5/CHANGES'
  - url: 'http://osvdb.org/36269'
  - url: 'http://secunia.com/advisories/25208'
  - url: 'http://secunia.com/advisories/29262'
  - url: 'http://www.debian.org/security/2008/dsa-1514'
  - url: 'http://www.ubuntu.com/usn/usn-458-1'
tags:
  - osv
  - pip
epss: 0.01486
epssPercentile: 0.72469
ingestedAt: '2026-07-08T18:25:48.409Z'
---

## Overview

MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.

## Affected packages

- `moin < 1.5.8`

## Remediation

Upgrade to a patched release:

- `moin 1.5.8`
