VYPR
Medium severity4.8NVD Advisory· Published Jul 10, 2026· Updated Aug 3, 2026

CVE-2026-57476

CVE-2026-57476

Description

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:deloitte:ai_assist_for_customer:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:deloitte:ai_assist_for_customer:*:*:*:*:*:*:*:*range: <2026-03-25
    • (no CPE)

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.