CVE-2026-57476

MEDIUM

Deloitte AI Assist for Customer unauthenticated RAG corpus read and write

Title source: cna
STIX 2.1

Description

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.

References (4)

Core 4

Scores

CVSS v3 4.8
EPSS 0.0025
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
Deloitte/AI Assist for Customer < 2026-03-25
Deloitte/AI Assist for Customer 2026-03-25
deloitte/ai_assist_for_customer < 2026-03-25
Published Jul 10, 2026
Tracked Since Jul 10, 2026