VYPR

AI Assist

by Microsoft

CVEs (3)

  • CVE-2026-57476Jul 10, 2026
    risk 0.00cvss epss 0.00

    Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network…

  • CVE-2026-57475Jul 10, 2026
    risk 0.00cvss epss 0.00

    Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted…

  • CVE-2026-57474Jul 10, 2026
    risk 0.00cvss epss 0.00

    Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network…