Impact
The vulnerability permits an attacker, unauthenticated but with knowledge of specific request parameters, to read data from or inject content into the retrieval‑augmented generation corpus of Deloitte AI Assist for Customer. This allows exfiltration of confidential information or corruption of the knowledge base, compromising both confidentiality and integrity of the application’s data. The weakness stems from a missing authentication control.
Affected Systems
The affected system is Deloitte AI Assist for Customer. No version qualifiers are available specifying the 2026‑03‑25 update that restricted network access and mandated authentication for formerly exposed endpoints. Any deployment that has not applied this update remains vulnerable.
Risk and Exploitability
The CVSS score of 6.3 combined with an EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack path involves contacting exposed API endpoints over the network; the attacker must know the exact endpoint patterns and required parameters, which is inferred from the description. Successful exploitation grants unauthenticated read or write access to the RAG corpus, compromising confidentiality and integrity of the application’s data.
OpenCVE Enrichment