Admin users can pass ACL, even though they don't have the specific role given in the ACLDescriptionAdmin users can pass ACL, even though they don't have the specific role given in the ACLSteps to Reproduce Login into any OOTB instanceCreate an ACL on the incident state fieldUncheck the admin overrides fieldGive a role which admin doesn't haveSave the ACLNow impersonate as any ADmin user and go to the incident tableOpen any incident recordWe are able to see the record is being editable by the admin userWorkaroundThis issue is under review. To receive notifications when more information is available, subscribe to this Known Error article by clicking the Subscribe button at the top right of the article. If you are able to upgrade, review the Fixed In field to determine whether any versions have a permanent fix.Related Problem: PRB1548463