Executive brief
Deloitte AI Assist for Customer, an enterprise AI platform used for customer service workflows, contained a security flaw where certain public-facing interfaces did not require a password. This allowed unauthorized individuals to send data to the system to modify its internal configuration. While the specific changes made during the discovery were not utilized by the system, the lack of authentication on these interfaces represented a significant security gap in a platform handling corporate data.
Technical details
The Deloitte AI Assist platform (internally known as Ascend) suffered from missing authentication (CWE-306) on several backend API endpoints exposed via Azure API Management. Specifically, the 'app-config' service accepted unauthenticated POST requests from the public internet. This allowed a remote, unauthenticated attacker to inject or modify configuration parameters. While the vendor stated these specific additions were not utilized by the system at the time of discovery, the vulnerability represented a failure in the authentication perimeter. The issue was remediated on 2026-03-25 by enforcing authentication and restricting network access to the affected endpoints.
Affected products
- Deloitte AI Assist for Customer (Ascend Platform) Versions prior to 2026-03-25
Timeline
- 2026-03-13: other: Initial discovery window began
- 2026-03-25: patched: Authentication enforced and network access restricted
- 2026-05-18: disclosed: Initial researcher advisory published
- 2026-07-10: advisory: CVE published to NVD