{"id":"CVE-2026-57476","title":"Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus","summary":"Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-306"],"vendor":"deloitte","product":"ai_assist_for_customer","affected":["ai_assist_for_customer < 2026-03-25"],"patched":["ai_assist_for_customer 2026-03-25"],"published":"2026-07-10","updated":"2026-07-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57476","references":[{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-57474","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://zerotolerance.me/advisories/assets/VU487875-deloitte-ascend-advisory.pdf","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://zerotolerance.me/advisories/deloitte-aiassist-ascend-2026-vu487875/","label":"9119a7d8-5eab-497f-8521-727c672e3725"}],"tags":["nvd"],"epss":0.00436,"epssPercentile":0.37341,"ingestedAt":"2026-07-17T13:12:07.974Z","slug":"CVE-2026-57476","body":"## Overview\n\nDeloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.\n\n## Affected\n\n- `ai_assist_for_customer < 2026-03-25`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ai_assist_for_customer 2026-03-25`","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}