Overview
During a review of NASA's [REDACTED] web presence, I found that content intended for an authenticated intranet was also reachable through a public route. The exposed material included an employee directory, links to individual profile pages, and internal presentation templates.
Administrative functionality remained protected. The issue did not provide elevated privileges or control over the affected system.
Discovery and validation
The expected intranet location required authentication. An alternative public-facing path, however, served equivalent resources without applying the same access restrictions.
I confirmed the behavior using only the minimum requests needed to establish impact. The hostname, URLs, paths, organizational unit, employee details, and reproduction targets are all replaced with [REDACTED] in this publication.

Impact
Unauthenticated visitors could access limited employee information and follow links to profile pages. Presentation templates intended for internal use were exposed through the same access-control inconsistency.
Because administrative content remained protected and the exposed information was not highly sensitive, the report was assessed as P4 / Low severity. The primary risk was privacy exposure and unintended access to internal resources.
Disclosure and resolution
I responsibly reported the issue to NASA with supporting evidence and private reproduction details. The report was accepted and the affected access-control behavior was resolved.
All hostnames, URLs, paths, organizational-unit names, employee details, and actionable reproduction information have been replaced with [REDACTED].