CVE-2026-57476 Details
Description
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.
A vulnerability in Deloitte AI Assist for Customer allowed unauthenticated access to API endpoints that could read from or inject content into the retrieval-augmented generation (RAG) corpus. This issue was present prior to March 25, 2026, and affected all tenant deployments of the AI Assist platform, including Deloitte's internal environments. The vulnerability was exploited by sending unauthenticated requests to specific backend API endpoints via the public Azure API Management gateway. This access permitted exfiltration of client documents and injection of malicious content into the RAG corpus, which could be presented as authoritative information through the platform's AI outputs.
As of the latest update, Deloitte has implemented authentication on the RAG service endpoints and removed the vulnerability from the production environment. However, organizations using a similar multi-tenant identity-fronted SaaS architecture should audit their API Management gateway logs for unauthenticated responses on the vulnerable endpoint patterns, review Keycloak administrative console access logs for unauthorized sessions, and conduct a RAG corpus audit for any unauthorized content ingested during the vulnerability window.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Technical Description |
| https://www.cve.org/CVERecord?id=CVE-2026-57476 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://zerotolerance.me/advisories/assets/VU487875-deloitte-ascend-advisory.pdf | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://zerotolerance.me/advisories/deloitte-aiassist-ascend-2026-vu487875/ | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| deloitte ai assist for customer | < 2026-03-25 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |