I noticed this evening that if a user is a subscriber to a blog and a administrator of another on a blog network, then from the admin-able blog they can multipost to the blog they subscribe to and the post actually is save to that other blog, defating the entire wordpress capabilities system.
It needs to check before posting.