Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.6%