Because... it can execute an arbitrary executable? In the old days, it also ran as root.
You could configure the server to be insecure by, eg, allowing cgi execution from a directory where uploaded files are stored.
I hesitate to suggest that you might be misremembering things that happened 30 years ago, but possibly you were using a very nonstandard setup?
For embedded devices (routers, security cameras, etc), it's very common to run CGI scripts as root.
So it is not even 30 years ago, it's still today, because of bad practices of the past.