Dovecot contains a flaw related to 'plugins/acl/acl-backend-vfile.c' interpreting an ACL permissions entry which may involve a user's private namespace and is of the same type as a previous ACL entry as an addition rather than a replacement. This may allow a remote authenticated attacker to use a request to read or modify a mailbox to bypass intended access restrictions.
Upgrade to version 1.2.15, 2.0.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.