Zero-Auth Flaw Exposes DoD Contractor to Cross-Tenant Data Breach

A critical authorization vulnerability recently discovered in Schemata, an AI-powered military training platform, left sensitive U.S. military personnel data and restricted training materials openly accessible to any low-privilege account for nearly 150 days before a patch was applied.

Schemata, backed by venture capital firm Andreessen Horowitz, holds active contracts with the United States Department of Defense to deliver immersive 3D simulation-based training to multiple military branches.

Security researcher Alex Schapiro, using the open-source AI hacking agent Strix, identified a complete absence of API authorization controls within the platform a flaw severe enough to allow unprivileged users to cross tenant boundaries and freely query data belonging to other organizations and individuals.

How the Zero-Auth Vulnerability Worked

The Strix agent began its assessment by establishing a low-privilege baseline account, then systematically mapped the Schemata application’s full API surface.

By observing standard application behavior and client-side route references, Strix replayed high-value data collection endpoints using only a regular, unprivileged session; no elevated credentials were required.

The results were alarming. The API completely failed to isolate tenants, returning platform-wide data rather than restricting responses to the authenticated user’s organization.

There were no meaningful permission checks or organizational scoping mechanisms on any of the affected endpoints.

Critically, write-enabled API routes were equally unprotected, meaning an attacker could have manipulated or permanently deleted core training infrastructure without any authentication barrier.

The data exposed through these unprotected endpoints was highly sensitive in nature. Any unprivileged account could query a complete platform-wide user directory, extracting full names, email addresses, and course enrollment data.

More dangerously, the exposed records included the specific military base assignments of active U.S. service members, information that could directly enable targeted phishing, social engineering, or doxing campaigns against military personnel.

The vulnerability also surfaced metadata and direct AWS S3 bucket links for hundreds of confidential training modules.

Among the exposed materials were proprietary 3D naval maintenance training assets and restricted U.S. Army field manuals covering the tactical deployment of explosive ordnance content that carries obvious national security implications if accessed by unauthorized parties.

The timeline surrounding the vulnerability disclosure highlights persistent challenges when reporting security flaws to organizations managing sensitive government data. Strix researchers first contacted Schemata on December 2, 2025.

The company’s initial response mischaracterized the disclosure as a solicitation for bug bounty payment rather than a good-faith security alert, creating unnecessary friction and delay.

Despite researchers clarifying their intent and sending multiple follow-up warnings about the critical and ongoing exposure, the vulnerability remained live for nearly 150 days.

Schemata ultimately acknowledged the issue and deployed a patch on May 1, 2026, just ahead of the scheduled public disclosure.

This timeline is particularly concerning given Schemata’s role as a DoD contractor. Organizations holding active Department of Defense contracts operate under strict federal compliance frameworks, including DFARS 252.204-7012 and Cybersecurity Maturity Model Certification (CMMC) requirements specifically designed to protect Controlled Unclassified Information (CUI).

A production platform serving active military data with no functional API authorization layer represents a foundational failure under these standards.

Government partners and military branches that used Schemata during the vulnerability window should immediately request access logs to assess whether unauthorized cross-tenant queries occurred and evaluate the extent of any potential data exposure.

The incident underscores the operational security risks that arise when immersive training platforms handling classified or sensitive military content are deployed without rigorous access control validation.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories