{"id":"CVE-2026-57474","title":"Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests","summary":"Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Ass…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"vendor":"deloitte","product":"ai_assist_for_customer","affected":["ai_assist_for_customer < 2026-03-25"],"patched":["ai_assist_for_customer 2026-03-25"],"published":"2026-07-10","updated":"2026-07-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57474","references":[{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-57474","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://zerotolerance.me/advisories/assets/VU487875-deloitte-ascend-advisory.pdf","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://zerotolerance.me/advisories/deloitte-aiassist-ascend-2026-vu487875/","label":"9119a7d8-5eab-497f-8521-727c672e3725"}],"tags":["nvd"],"epss":0.00514,"epssPercentile":0.42765,"ingestedAt":"2026-07-17T13:12:07.924Z","slug":"CVE-2026-57474","body":"## Overview\n\nDeloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.\n\n## Affected\n\n- `ai_assist_for_customer < 2026-03-25`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ai_assist_for_customer 2026-03-25`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}