The /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following:
Fixed in v1.83.0. The endpoint now requires proxy_admin role.
Restrict API key distribution. There is no configuration-level workaround.