CVE-2026-19485: Google Cloud Vertex Ai Search For Commerce

Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.

Affected products

  • Google Cloud Vertex Ai Search For Commerce: before 2026-04-27 (fixed in 2026-04-27)

Published 2026-08-26. Last modified 2026-08-31.