A security issue has been reported in MoinMoin, which can be exploited by malicious users to bypass certain security restrictions. The security issue is caused due to an error when processing hierarchical ACLs, which can be exploited to access restricted sub-pages. Successful exploitation requires that the username does not match any of the of the sub-page's ACLs and that hierarchical ACL processing is enabled (not the default).
CVE-2009-4762 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4762): MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603.