CyberRota Analysis
AI-GeneratedDeloitte AI Assist for Customer is vulnerable due to its acceptance of unauthenticated POST requests through public-facing API endpoints, enabling remote attackers to make limited configuration changes that are not utilized by the system. Although the impact is moderate, organizations using this product should prioritize addressing this vulnerability to prevent potential exploitation, especially in environments where sensitive data may be processed. Immediate action is recommended to ensure proper authentication and network access controls are in place.
Original NVD Description
Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.
Related CVEs
Other vulnerabilities affecting the same vendor(s)