CVE-2026-19485
Bucket Squatting in Vertex AI Search for Commerce
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.
| CWE | CWE-330 |
| Vendor | google cloud |
| Product | vertex ai search for commerce |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud vertex ai search for commerce
Be the first to know when new unknown vulnerabilities affecting google cloud vertex ai search for commerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google Cloud / Vertex AI Search for Commerce
0 < 2026-04-27
References
Credits
๐ Omer Amiad