SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-57474

MEDIUM · CVSS 5.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Deloitte AI Assist for Customer exposed sensitive configuration information via unauthenticated public API endpoints, potentially aiding attackers in reconnaissance efforts. Although the vulnerability has been mitigated as of March 25, 2026, organizations using this product should prioritize reviewing their API security practices to prevent similar exposures in the future.

CVE
CVE-2026-57474
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%

Original NVD Description

Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.

Related CVEs

Other vulnerabilities affecting the same vendor(s)