Tuesday, September 8, 2026

Zero-Auth Vulnerability Enables Cross-Tenant Access at DoD Contractor

A severe authorization vulnerability was recently discovered in Schemata, an AI-powered virtual training platform serving the United States Department of Defense.

Security researcher Alex Schapiro, utilizing the open-source AI hacking agent Strix, identified a critical lack of API authorization. Backed by Andreessen Horowitz, Schemata holds active government contracts to provide immersive 3D simulations for various military branches.

This zero-auth flaw allowed unprivileged accounts to access sensitive military training materials and personnel records across different tenant boundaries, highlighting a significant operational security risk.

Zero-Auth Vulnerability

The automated Strix agent established a low-privilege baseline to map the Schemata application’s reachable API surface. By observing normal application behavior and client-side route references, the tool replayed high-value collection endpoints using a standard, unprivileged session.

The system failed to isolate tenants, returning data for the entire platform rather than restricting it to the specific user or organization. The API lacked any meaningful organizational scoping or permission checks.

Furthermore, the absence of authorization checks on write-enabled routes meant attackers could potentially manipulate or permanently delete critical training infrastructure.

The exposed endpoints provided direct access to an alarming volume of sensitive intelligence. Unprivileged accounts could query the complete user directory to extract full names, email addresses, and enrollment data.

Crucially, this included the specific military base deployments of active U.S. service members, leaving them highly vulnerable to targeted phishing or doxing campaigns. The vulnerability also exposed metadata and direct AWS S3 links for hundreds of confidential modules for military operations.

These compromised assets included proprietary 3D naval maintenance training materials. They restricted Army field manuals concerning the tactical deployment of explosive ordnance.

The vulnerability disclosure timeline illustrates significant challenges in security reporting. Strix researchers first contacted Schemata on December 2, 2025.

The company leadership’s initial response incorrectly assumed the disclosure was an attempt to solicit a bug bounty payment. Despite researchers clarifying their intent and sending multiple follow-up warnings about the critical exposure, the vulnerability remained live for nearly 150 days.

Schemata finally acknowledged the exposed endpoints and successfully patched the system on May 1, 2026, immediately before the scheduled public disclosure.

Organizations maintaining active Department of Defense contracts operate under strict federal regulations, including DFARS 252.204-7012 and CMMC requirements for handling Controlled Unclassified Information.

A platform that serves military data without a functional API authorisation layer constitutes a foundational cybersecurity failure. Government partners using Schemata should request access logs as soon as possible to verify data integrity and assess potential exposure during the vulnerability window.

Software developers must prioritize robust tenant isolation, continuous automated security validation, and maintain open channels for independent security researchers.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Related Articles

Recent News