I am not sure the rights offered in that bug are fully ok: generally you 
wouldn't want the configs to be writable by the service daemon if you can avoid 
it (so if it's hacked - it can be abused to a lesser extent). I think the only 
writable bit is the killpower file, which might better belong in /var/run/nut 
or state-dir or something like that. Maybe something for nut-cgi needs writes? 
Otherwise root:nut 640 should be good, IMHO. Maybe even different users for 
server/driver/clients, for paranoid setups...

