cfaa has broad interpretations

AFAIK it's been interpreted that getting public data while being someone the data holder doesn't like is, unusually, one of the very few things that is not a CFAA violation. Bright Data vs X for example.

So long as the "getting" doesn't consist of circumventing something that is ostensibly a security mechanism, such as a URL that had never been presented to you by the server but is fairly easily guessed.

You mean vs Meta