Impact
The flaw allowed unauthenticated callers to a public API to obtain sensitive configuration data, briefly leaking information that could help an attacker reduce reconnaissance efforts. The weakness aligns with CWE-200, where insufficient authentication leads to information exposure. The disclosure does not directly enable execution or compromise, but the data other attacks.
Affected Systems
The vulnerability impacts the Deloitte AI Assist for Customer product. No specific version information is listed in the CNA data, so all currently deployed instances that expose the affected API endpoints are potentially affected.
Risk and Exploitability
Based on the CVSS score of 6.9, the vulnerability is moderate, indicating a plausible but not trivial exploitation path. EPSS score of <1% indicates a very low exploitation probability, and it is also not listed in CISA’s KEV catalog. The attack vector is likely a remote, internet-based request to the public API, which was inferred from the description that the API accepted unauthenticated requests. Since the product introduced network restrictions and authentication on 2026-03-25, the likelihood of successful exploitation should be reduced.
OpenCVE Enrichment