CVE-2014-4446: Apple OS X Server

Low severity, CVSS 2.1. EPSS: 1.4% chance of exploitation in the next 30 days.

Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a change made by an administrator.

Affected products

  • Apple OS X Server: up to and including 3.1.2

Published 2014-10-18. Last modified 2026-06-17.