Remote Code Execution Vulnerability in Google Cloud Gemini Enterprise Agent Platform SDK for Python
CVE-2026-19407

7.7HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-19407?

The Google Cloud Gemini Enterprise Agent Platform SDK for Python contains a vulnerability that allows attackers to exploit bucket squatting techniques, leading to the potential for remote code execution and the theft of tenant-project tokens. This issue is present in versions prior to 1.166.1, posing significant security risks for users relying on this SDK. It is crucial for users to update to the latest version to mitigate these risks.

Affected Version(s)

Gemini Enterprise Agent Platform SDK for Python 1.16.0 < 1.165.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ori Hadad
.