That's not an inherent problem, that's poor implementation.
Procedures like this could work:
Person contacts support requesting a bypass of the 2FA due to whatever reason.
1. Cloudflare sends email to persons account notifying of the request.
2. Person is required to upload photographic proof of two govt-issued id's.
3. Cloudflare calls person (phone number on file from 2FA or account setup).
4. 30 day delay initiated.
5. 30 days layer, Cloudflare emails and calls person to confirm they requested 2FA bypass.
6. Access is granted.
With procedures like this, it's no longer about convincing a support rep.
It goes like this: If you can prove who you are, you get access to your account. That's what this is all about.
The more offline, human touch we go, the greater the security.