Access to administrative-level operational data across organisations, including campaign scheduling, assignee identities, and admin-flag exposure. The isAdmin field in the response is the specific detail that turns this from an information disclosure into a targeting primitive: an attacker who has already gained low-privilege access on any tenant can now enumerate which named accounts on other tenants carry admin privileges, and use that list as a target set for phishing or credential stuffing.
Combined with F-03, the same low-privilege session pulls a full read of who is running what campaign, when, and under whose admin oversight, for every tenant on the system. That is a materially better position than a full-tenant BOLA on its own, because it maps identities to authority.