After all, it got them this responsible disclosure.
It wasn't part of the vulnerability, it just allowed OP (who happened not to be legitimately in the beta) to find it.
this isn't some kid writing their first dynamic webpage, it's a public multinational that proxies a large percentage of the internet as security product
the fact this wasn't caught internally is extremely worrying and makes me wonder what other sort of basic quality issues they have lurking
But client managing to opt itself in to a beta, as my GP comment was about, is no big deal. Worst case you're getting something free that you're supposed to pay for.
Beta security shouldn't be worse than the rest of prod, private beta members shouldn't be trusted more than non-members; so if the odd non-member finds a way in it's fine.
Not at all. How often do people complain of temporary solutions becoming permanent? Doing it wrong out of the gate is a surefire way to ensure it makes it to production if there's no further review.
The beta feature had a very bad bug that allowed hijacking other people's email. That is entirely independent of controlling access to the beta feature.
It's only mentioned in the write-up because OP wouldn't have been able to explore bugs in the beta feature without finding access to it first, which he didn't otherwise have.
Do we really think Cloudflare Email Routing private beta was private to somehow trusted parties only though? Presumably 'N-mutual trusted parties' too, for regulatory compliance. I assume not; not least because the product security lead is here in the comments saying they vetted logs etc. after the fact to ensure that only OP took advantage of this.
Ideally you want both but it doesn't always work out that way.