CVE-2026-19485 CRITICAL

CVE-2026-19485: Bucket Squatting in Vertex AI Search for Commerce

Vendor Google Cloud
Product Vertex AI Search for Commerce
Weakness CWE-330 · Insufficient randomness
Published August 26, 2026
Last update August 26, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/U:Clear

What the vulnerability does

01Description

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.

Key dates

02Disclosure timeline

August 26, 2026 CVE published
August 26, 2026 Record updated

Related vulnerabilities

04Related CVE