This seems to be a security issue, if end-customers are able to grant itslef read-access to other vhost/environments.
A random user is able to read data on the whole server, like /etc/shadow, various PHP files or database passwords?
Please explain why every end-customer must can change this...