Skip to content
Google CloudCVE-2026-19485

Google Cloud Vertex AI Search for Commerce: weak randomness

Critical9.3CVE-2026-19485 · Published Aug 26, 2026 · updated Aug 31, 2026

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.

Google Cloud advisory

Affected versions

PackageAffectedFixed in
Vertex AI Search for Commerce
Product
< 2026-04-272026-04-27
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-330

More Google Cloud advisories

All Google Cloud
Advisory
Google Cloud Agent Development Kit (ADK): path traversal
High8.7Sep 4
Google Cloud Integration Connectors: missing authorization
High8.5Sep 4
Google Cloud Build: improper authorization
Critical9.4Aug 31
Google Cloud BigQuery Data Transfer Service: improper input validation
Critical9.4Aug 26
Google Cloud Application Integration: missing authorization
Critical9.3Aug 22
Google SecOps (Chronicle SOAR): SQL injection
Critical9.4Aug 17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.