CVE-2014-4446: Apple OS X Server
Low severity, CVSS 2.1. EPSS: 1.4% chance of exploitation in the next 30 days.
Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a change made by an administrator.
Affected products
- Apple OS X Server: up to and including 3.1.2
Published 2014-10-18. Last modified 2026-06-17.