Hello,
I suppose you are talking about SAP NetWeaver Java?
I could not reproduce your problem. If I login with a simple user I get "You do not have permission to administrate SPNEGO"
Possibly the user have additional rights (see Identity Management: Assigned Roles and Assigned Groups), or the permissions within the default groups (Authenticated Users, Everyone) where changed.
That may also be valid if a LDAP/Active Directory is attached to the UME and a LDAP group the user is a member of (e.g. AD: "Domain Users") have some admin roles assigned.
You also get logged in "automatically" if you already logged in with an administrator account in the NetWeaver Administrator (NWA) and open another NWA page (e.g. SPNego) in the same web browser. This works as designed.
Please check again.
Grüße / Kind regards,
Frank