CVE-2026-19485
Received Received - Intake

Predictable Resource Name in Google Cloud Vertex AI Search for Commerce

Vulnerability report for CVE-2026-19485, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: GoogleCloud

Description

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google cloud_vertex_ai_search_for_commerce to 2026-04-27 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Predictable Resource Name issue in BigQuery Import Staging within Google Cloud Vertex AI Search for Commerce. It affects versions before 2026-04-27 and allows attackers with knowledge of a victim's project number to access staged data and error logs through predictable bucket names.

Detection Guidance

This vulnerability is specific to Google Cloud Vertex AI Search for Commerce and does not require manual detection as it was patched and no customer action is needed. The issue involves predictable bucket names in BigQuery Import Staging.

Impact Analysis

An attacker could gain read/write access to your staged data and error logs if they know your project number. This could lead to unauthorized data exposure or manipulation of your information.

Compliance Impact

The vulnerability allows an attacker to gain read/write access to staged data and error logs through predictable bucket names. This could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (healthcare data privacy) compliance requirements by exposing personal or protected health information.

Mitigation Strategies

No immediate action is required as this vulnerability was already patched by Google Cloud. Ensure your Vertex AI Search for Commerce is updated to version 2026-04-27 or later.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19485. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart