Description
Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.
Published: 2026-07-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allowed unauthenticated callers to a public API to obtain sensitive configuration data, briefly leaking information that could help an attacker reduce reconnaissance efforts. The weakness aligns with CWE-200, where insufficient authentication leads to information exposure. The disclosure does not directly enable execution or compromise, but the data other attacks.

Affected Systems

The vulnerability impacts the Deloitte AI Assist for Customer product. No specific version information is listed in the CNA data, so all currently deployed instances that expose the affected API endpoints are potentially affected.

Risk and Exploitability

Based on the CVSS score of 6.9, the vulnerability is moderate, indicating a plausible but not trivial exploitation path. EPSS score of <1% indicates a very low exploitation probability, and it is also not listed in CISA’s KEV catalog. The attack vector is likely a remote, internet-based request to the public API, which was inferred from the description that the API accepted unauthenticated requests. Since the product introduced network restrictions and authentication on 2026-03-25, the likelihood of successful exploitation should be reduced.

Generated by OpenCVE AI on July 29, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the vendor‑issued update that enforces authentication on the exposed endpoints.
  • Configure firewall or application API exposure to internal or VPN‑connected clients only.
  • Continuously monitor API traffic for unauthenticated requests and terminate any that attempt to retrieve configuration data.

Generated by OpenCVE AI on July 29, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Deloitte
Deloitte ai Assist For Customer
Vendors & Products Deloitte
Deloitte ai Assist For Customer

Fri, 10 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.
Title Deloitte AI Assist for Customer information disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Deloitte Ai Assist For Customer
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-07-21T17:06:47.452Z

Reserved: 2026-06-24T13:52:00.373Z

Link: CVE-2026-57474

cve-icon Vulnrichment

Updated: 2026-07-21T17:06:43.401Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor