Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
You can sell it to others. Zerodium buys 0days for 10 times or more than the original bounties. https://zerodium.com/program.html
It's not even cut-and-dried for the RCEs that firms like this do buy. Bounty programs at giant tech companies are generally aware of the market prices for RCEs and are not overtly trying to screw you over. The flip side is that the price you get from a broker is (1) negotiated and (2) tranched, so the "number" you get is a best-case, not guaranteed, and can collapse if the bug is burned before the IC agencies the broker sells it to finish using it to hurt people. The bounty number, on the other hand, is a sure thing.
But ~nobody is buying auth bypass vulnerabilities. Maybe if you can mint OG Twitter accounts and aren't worried about going to prison.