Sensitive Information Exposure in Agentspace Service by Google
CVE-2026-1727
What is CVE-2026-1727?
The Agentspace service has a security flaw that allowed sensitive information to become vulnerable due to the reliance on predictable naming conventions for Google Cloud Storage (GCS) buckets. These names were used for logging errors and temporarily staging data imports from GCS and Cloud SQL. The predictability of the bucket names enabled attackers to exploit this weakness through 'bucket squatting', creating their own buckets prior to the legitimate user's utilization. Updates implemented after December 12, 2025, have addressed this vulnerability, requiring no action from users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Gemini Enterprise (formerly Agentspace) 0 < 12/12/2025
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
