PT-2026-57259 · Deloitte · Ai Assist For Customer
CVE-2026-57476
·
Published
2026-07-10
·
Updated
2026-07-21
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Deloitte AI Assist for Customer (affected versions not specified)
Description
Unauthenticated API endpoints were exposed, allowing an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. RAG is a technique used to optimize the output of a large language model by referencing an authoritative knowledge base outside of its training data.
Recommendations
Restrict network access and enforce authentication for the exposed API endpoints.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai Assist For Customer