This vulnerability was patched and no customer action is needed.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed. | |
| Title | Bucket Squatting in Vertex AI Search for Commerce | |
| Weaknesses | CWE-330 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-08-26T19:04:26.776Z
Reserved: 2026-08-10T16:19:58.910Z
Link: CVE-2026-19485
Updated: 2026-08-26T19:04:08.963Z
Status : Received
Published: 2026-08-26T19:16:49.157
Modified: 2026-08-26T19:16:49.157
Link: CVE-2026-19485
No data.
OpenCVE Enrichment
No data.