Admin security gaps found by the SPF.28 recon. POST /_admin/sites//properties, properties/delete and theme have no permission check. GET /admin/farm/permissions, /admin/services and /admin/seats are open to any caller, although Central Administration, which links them, is farm-admin only. Gate them: farm pages on SitePolicy.IsFarmAdministrator, site pages on Full Control of the site.