Account portal
You are not signed in.
An admin is signed in on their own browser. The endpoint POST /account/email updates the signed-in user's email and has no CSRF protection.
Host an attacker page with POST /notes, then have the admin visit it via the bot.