Multi-Factor Authentication Enrollment Vulnerability

Multi-Factor Authentication Enrollment. Another user is able to delete the Configured MFA Authentication of another user as long as the credential Id is known. Is there away to avoid this vulnerability. If not is it possible to fix this in a future release.