This all sounds somewhat like the original example given for the Confused Deputy Problem.

Maybe someone can comment about whether SELinux capabilities would be good safety net against such mishaps.

