Dovecot contains a flaw related to 'plugins/acl/acl-backend-vfile.c' interpreting a less specific ACL permissions entry of the same type as a previous more specific ACL entry as an addition rather than a replacement. This may allow a remote authenticated attacker to use a request to read or modify a mailbox to bypass intended access restrictions.
Upgrade to version 1.2.15, 2.0.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.