Dovecot contains a flaw related to the ACL plugin granting admin permissions to mailbox owners in non-public namespaces. This may allow a remote authenticated attacker to bypass intended access restrictions by changing a mailbox's ACL.
Upgrade to version 1.2.15, 2.0.beta2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.