A vulnerability has been identified in Dovecot, which could be exploited by local attackers to bypass security restrictions. This issue is caused due to insecure permissions (777) being set on the "base_dir" directory and its parents, which could allow malicious users e.g. to replace auth sockets and log in as other users.