JacquesLim Even though there is a permission exception handler, there are some underlying cold-written rules with group permissions / visibility scopes that probably have room for improvement if you're looking for a more specific error ? Resources aren't found without permission sometimes, it's best to check perms either way when debugging
It's also a result of your own configuration: if you let Everyone see/read topics, you should expect the same audience to potentially click a profile. Probably some other underlying reasons (list users API) to encourage the permission at this point, I think it should eventually be removed or default to like-similar settings as to avoid confusion