Junglewise Threat Intelligence

CVE-2026-57474: Deloitte AI Assist for Customer Information Disclosure in API Endpoints

CVE-2026-57474 · Severity: medium · CVSS 5.3 · Published 2026-07-10

Executive brief

Deloitte AI Assist for Customer, an enterprise AI platform used for customer service workflows, was found to have several public-facing API endpoints that did not require authentication. This allowed anyone on the internet to view internal configuration information about the platform. While this specific issue did not directly expose customer data, it provided technical details that could help an attacker plan more sophisticated strikes against the system.

Technical details

The vulnerability is a case of sensitive information disclosure (CWE-200) resulting from missing authentication (CWE-306) on specific backend API endpoints. Publicly accessible endpoints, including those associated with the 'app-config' service, responded to unauthenticated HTTP requests with internal configuration data. This allowed remote, unauthenticated attackers to perform reconnaissance and gather technical details about the platform's architecture and environment. The issue was part of a broader set of vulnerabilities identified in the Deloitte Ascend platform. Deloitte remediated the issue on 2026-03-25 by restricting network access and enforcing authentication requirements for the affected endpoints.

Affected products

  • Deloitte AI Assist for Customer (Ascend Platform) Versions prior to 2026-03-25

Timeline

  • 2026-03-13: other: Initial observation by researchers
  • 2026-03-25: patched: Authentication enforced and network access restricted
  • 2026-05-18: disclosed: Researcher advisory published
  • 2026-07-10: advisory: CVE published to NVD

References

Related threats