A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names.
This vulnerability was patched and no customer action is needed.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 19:16
Updated : 2026-08-31 18:50
NVD link : CVE-2026-19485
Mitre link : CVE-2026-19485
CVE.ORG link : CVE-2026-19485
JSON object : View
Products Affected
No product.
CWE
CWE-330
Use of Insufficiently Random Values
