I've just created an empty account, and turns out it has the power to upvote posts in the main section, effectively creating 10 Karma points for another account out of thin air. This is a serious vulnerability: if calcsam is indeed a figurehead of a Mormon conspiracy (!), most of the upvotes on the posts could come from such dummy accounts.
This is a serious vulnerability
I'd question that. I'd call it "a bit of a vulnerability."
tl;dr: it's not a problem unless and until it's actually a problem.
I just noticed that calcsam, who just posted two top posts in the main section of the site, only has the 100 karma that he has, so far, gained from those posts.
I don't object to those posts being there, but how did he do that?
Edit: Question answered; Eliezer mucked around with the karma system to make this possible in this specific case.