logo

A DOD contractor’s API flaw exposed military course data and service member records

ID: fc1bf9be-f6f6-5c83-a87d-89b2adc132d2

STIX ID: report--fc1bf9be-f6f6-5c83-a87d-89b2adc132d2

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Greg Otto

...
...

A security researcher (Strix) found that Schemata’s AI-powered virtual training platform exposed sensitive military training materials and hundreds of user records via API endpoints that lacked proper authorization, enabling a low-privilege account to access data across multiple tenants; Schemata acknowledged the issue, patched the endpoints after a prolonged disclosure process, and said there is no evidence of third-party exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.