Making it worse, they actively sold this as a multi-tenant platform to be used with mutually untrusting parties.
When I met with engineering and started to explain, they started smiling and said "this is a known issue and we're going to fix it in our next version."
Quite some time later I ran across people using it in the wild and they had not passed a lot of the glaring holes. Even their newer version had a hidden input field on the edit profile page named "IsAdmin". This did exactly what you think.
They ended up having a successful exit as far as I know and I've never heard anyone speak ill of them security-wise.
Telecom is a mess. These holes are easily exploitable for direct profit. But there's so much more low-hanging fruit, I don't think people bother.