As Tim said, this has been like this as long as I know ClearPass. While the naming of the ports, and the way you interpreted it, may not fully cover your intended use, the documentation doesn't tell that the admin UI is unreachable via the data port. And indeed, service ACLs were introduced to stop admin access in dual port cases.
For the sake of simplicity and security, I always try to just use the management port (don't configure data port). Then at least you know what you get and can do proper designs around it. There are very few cases where the data port is actually needed, and in those cases, it can be better to still just use the management port. Unless you fully understand the implications of dual port configuration, I would try to avoid the use of it.
To learn more about the routing and working of dual port ClearPass, please check the CPPM Service Routing TechNote.