It has been reported that the user form processing in the file
userform.py does not properly manage users when using Access Control
Lists or a non-empty superusers list.
A remote attacker could exploit this vulnerability to gain superuser
privileges on the application.