I noticed that the embed_default display does not have any access checks. Is this on purpose?
Add an access configuration to the view to limit visibility based on user role.
Active
6.2
Code