Yes, but the bitcoind reference client fails safely: the child transactions are orphaned and no funds are lost. It's behavior alone is not exploitable.
It is not "lose money" exploitable (unless combined with social engineering) but is definitely "lose time, lose effort" exploitable.