No - simply put: fax2email exposed an object reference to an internal implementation object (in their case files and directories) without an access control check or other form of protection, hence allowing anyone having received a fax to just log into the system and do a URL traversal to view other customers data. This is poor programming and ignorance about security and I would not be surprised if the system allowed elevated administrative access and SQL injection as well to gain access to other data.
A hacker could easily sign up for an account, receive fax and then use the session to access other customers data. It is puzzling that companies like Cognition demonstrate such arrogance, rather than a simple "We messed up and thanks to the researcher we managed to patch up the issue" - security issues will always occur and working with security researchers adds tremendous value to any business.
FWIW - in our business we have close relationship to a number of security researchers and offer a bug-bounty programme to find and resolve bugs and security issues and it is something parastatals and big corporates should embrace - the value proposition and insight gained from outsiders is invaluable.