It's not a bug.
This is true for both Windows and UNIX. For instance, we can boot up Solaris from CD-ROM, enter single user mode and modify almost everthing including root password.
So I don't think it's a bug. It's a common practice to allow whoever has physical access to the system to gain full control of it.
