SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19485

CRITICAL · CVSS 9.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A Predictable Resource Name vulnerability in Google Cloud Vertex AI Search for Commerce allows attackers with knowledge of a victim's project number to gain unauthorized read/write access to staged data and error logs due to predictable bucket naming. Organizations utilizing affected versions prior to April 27, 2026, should prioritize this issue to ensure their data remains secure, although no immediate action is required since the vulnerability has been patched.

CVE
CVE-2026-19485
Severity
CRITICAL
CVSS
9.3
EPSS
0.23%

Original NVD Description

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.