CVE-2026-19485: Google Cloud Vertex Ai Search For Commerce
Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.
Affected products
- Google Cloud Vertex Ai Search For Commerce: before 2026-04-27 (fixed in 2026-04-27)
Published 2026-08-26. Last modified 2026-08-31.