Predictable Resource Name Vulnerability in Google Cloud Vertex AI Search for Commerce
CVE-2026-19485

9.3CRITICAL

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2026-19485?

A predictable resource name vulnerability exists in the BigQuery Import Staging feature of Google Cloud Vertex AI Search for Commerce. This flaw allows an attacker who is aware of the victim's project number to gain unauthorized read/write access to sensitive staged data and error logs through predictable bucket names. Google has released a patch for this vulnerability, ensuring that no further customer action is needed for protection.

Affected Version(s)

Vertex AI Search for Commerce 0 < 2026-04-27

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Omer Amiad
.