According to the docs, to create a list, a Sites.ReadWrite.All application permission is needed.
Sites.ReadWrite.All
I have an Azure app with exactly that permission: