Google CloudCVE-2026-19407
Google Cloud Gemini Enterprise Agent Platform SDK: remote code execution
High7.7CVE-2026-19407 · Published Sep 15, 2026 · updated Sep 21, 2026
Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Gemini Enterprise Agent Platform SDK for Python Product | >= 1.16.0, < 1.165.1 | 1.165.1 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-330
More Google Cloud advisories
All Google Cloud| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | Google Cloud Gemini Enterprise: server-side request forgery | High8.7 | 2026-06-01 |
| Sep 10 | Google Cloud Gemini CLI: code execution | High7.7 | 0.39.1 |
| Sep 9 | Google Cloud Agent Development Kit (ADK) for Python: code injection | Critical10.0 | 2.7.0 |
| Sep 4 | Google Cloud Agent Development Kit (ADK): path traversal | High8.7 | 1.22.0 |
| Sep 4 | Google Cloud Integration Connectors: missing authorization | High8.5 | 2025-12-11 |
| Aug 31 | Google Cloud Build: improper authorization | Critical9.4 | 2026-06-24 |