An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.