CVE-2026-57476
- EPSS 0.25%
- Veröffentlicht 10.07.2026 17:10:50
- Zuletzt bearbeitet 03.08.2026 19:16:47
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for C...
CVE-2026-57475
- EPSS 0.34%
- Veröffentlicht 10.07.2026 17:10:35
- Zuletzt bearbeitet 03.08.2026 19:16:47
Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI A...
CVE-2026-57474
- EPSS 0.29%
- Veröffentlicht 10.07.2026 17:10:15
- Zuletzt bearbeitet 21.07.2026 18:17:02
Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Custo...