CVE-2026-19485

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-26 19:16

Updated : 2026-08-31 18:50


NVD link : CVE-2026-19485

Mitre link : CVE-2026-19485

CVE.ORG link : CVE-2026-19485


JSON object : View

Products Affected

No product.

CWE
CWE-330

Use of Insufficiently Random Values