I suggest that it should be considered a vulnerability if it's a vulnerability in any possible configuration. Consider a bug in some obscure device driver that about three people use. If it's exploitable, it should count as a vulnerability, though perhaps not the most serious one. The number of people who run with SELinux turned off is greater than three.