SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-57476

MEDIUM · CVSS 4.8 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Deloitte AI Assist for Customer has exposed unauthenticated API endpoints that could allow attackers to read from or inject content into the retrieval-augmented generation (RAG) corpus. Although network access was restricted and authentication enforced on March 25, 2026, organizations using this product should prioritize patching and monitoring to mitigate potential data exposure risks. This vulnerability is particularly relevant for security teams and developers managing API integrations within their systems.

CVE
CVE-2026-57476
Severity
MEDIUM
CVSS
4.8
EPSS
0.25%

Original NVD Description

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.

Related CVEs

Other vulnerabilities affecting the same vendor(s)