The behavior is correct because it enables to create VPNs between devices of different OUs. Possible use-case would be a Supplier => Manufacturer scenario. The button should be and is currently disabled if you do not have configuration rights at all, whether implicitly via OUs or directly for devices.
I see that in that case you are not able to use the VPN policies though, which is a bug.
the problem can be reproduced when a backup pre 2.050 is installed. The OU of the ipsec policies is not updated correctly when the backup is installed. We will fix the problem for the next release.