I confirm that ANYONE can hijack a nova spice console with a spice client command like "spicec -h compute-address -p <5901-5999>

This is on a standard three node build following the latest OPENSTACK INSTALLATION GUIDE FOR UBUNTU 12.04/14.04. Then spice console was configured instead of novnc.