In some situations, users without the permission "edit contributions" could edit recurring contributions.
CiviCRM version 5.28.0 and earlier
CiviCRM version 5.28.1 and 5.27.5 ESR
Upgrade to the latest version of CiviCRM
Jens Schuppe for reporting the issue
Eileen McNaughton of Wikimedia and Seamus Lee of CiviCRM Core Team for fixing the issue
dev/core#1945