CyberRota Analysis
AI-GeneratedDeloitte AI Assist for Customer exposed sensitive configuration information via unauthenticated public API endpoints, potentially aiding attackers in reconnaissance efforts. Although the vulnerability has been mitigated as of March 25, 2026, organizations using this product should prioritize reviewing their API security practices to prevent similar exposures in the future.
Original NVD Description
Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.
Related CVEs
Other vulnerabilities affecting the same vendor(s)