Felix Dewaleyne reported in https://bugzilla.redhat.com/show_bug.cgi?id=1382756: Description of problem: requests made from the web_ui can allow a user not having any permission on a vm to run any action on it Version-Release number of selected component (if applicable): 5.5.4
This issue has been addressed in the following products: CloudForms Management Engine 5.6 Via RHSA-2016:2091 https://rhn.redhat.com/errata/RHSA-2016-2091.html