Impact
The flaw allows an attacker to send POST requests to public API endpoints without authentication, appending configuration entries that the system ignores. The vulnerability arises from a missing authentication check (CWE-306). While the attacker cannot alter active system operation, the presence of unauthorized data could indicate intrusion attempts or future use if system logic changes.
Affected Systems
The affected product is Deloitte AI Assist for Customer, a cloud‑based AI assistance service. No specific version is listed, but the issue existed before March 25 2026 when the service exposed write endpoints to the public internet.
Risk and Exploitability
The CVSS score of 6.9 vulnerability was not listed in CISA KEV, and the EPSS score is < 1%, indicating a very low likelihood of exploitation. Based on the description, unauthenticated HTTP POST requests over the public network to the exposed API endpoints. After March 25 2026 the publisher restricted network access and required authentication, limiting the window for exploitation.
OpenCVE Enrichment