CVE-2026-19407 HIGH

CVE-2026-19407: GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDK

Vendor Google Cloud
Product Gemini Enterprise Agent Platform SDK for Python
Weakness CWE-330 · Insufficient randomness
Published September 15, 2026
Last update September 17, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Clear

What the vulnerability does

01Description

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Key dates

02Disclosure timeline

September 15, 2026 CVE published
September 17, 2026 Record updated

Related vulnerabilities

04Related CVE