๐Ÿ” CVE Alert

CVE-2026-19485

UNKNOWN 0.0

Bucket Squatting in Vertex AI Search for Commerce

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.

CWE CWE-330
Vendor google cloud
Product vertex ai search for commerce
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud vertex ai search for commerce

Be the first to know when new unknown vulnerabilities affecting google cloud vertex ai search for commerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Vertex AI Search for Commerce
0 < 2026-04-27

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
unit42.paloaltonetworks.com: https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/

Credits

๐Ÿ” Omer Amiad