It's not "request from a fuel pump". The CAN bus is a broadcast medium with addresses roughly equivalent to object type tags. So your ABS controller is sitting there repeatedly broadcasting messages like LEFT_FRONT_WHEEL_SPEED = 45mph, or whatever. But anything else connected to that pair of wires can send the same type of message, even though it's not the ABS controller.
Like ethernet, this points towards the paradigm for analyzing security of such buses. For example in an office environment, a link trunking a bunch of VLANs is going to be in server rooms or enclosed in conduit/walls/etc, whereas the ports in individual offices are going to be locked down to specific VLANs, perhaps only to specific MAC addresses, etc.
In other words, yes there are always vulnerabilities to certain types of physical access. But that does not mean that all physical access implies game over. For instance a computer should be secure against attacks attempted from the USB bus, then you might have a case tamper switch that kills the rig, preventing easy access to the PCIe bus which is much more privileged.
Translated to a car, this probably means that non-security-critical devices close to the periphery (like headlights) should be on a separate bus to things like door locks, keyfob receivers, etc. AFAIK my car already has two separate CAN buses, bridged by the gauge cluster. The distinction has to do with hard realtime messages from critical systems (engine, steering, ABS, etc), and less critical messages of turning lights on/off etc. We can imagine one or two more buses with distinctions based on security.