CVE-2026-19485

Summary

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names.

This vulnerability was patched and no customer action is needed.

Affected Software

VendorProductVersion RangeStatus
Google CloudVertex AI Search for Commerce0 < 2026-04-27affected

Weaknesses

  • CWE-330: CWE-330 Use of Insufficiently Random Values

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References