Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.