Sure, but cookies are only a small part of the problem. It's not enough.
Otherwise its no different then doing curl on the attacker's machine.
There are other cases. Does you company have internal tools exposed via the intranet? If you happen to know the URI scheme, from say an ex-employee, you're able to exfiltrate information if you get a current employee on VPN to open your page. This becomes a tool in a layered attack. Sure it's careless to have such anonymous endpoint on your intranet. But there's a reason why anonymous images can't be plainly read back.
Securing your services regardless of where they are in the network should be go the go to