CyberRota Analysis
AI-GeneratedA Predictable Resource Name vulnerability in Google Cloud Vertex AI Search for Commerce allows attackers with knowledge of a victim's project number to gain unauthorized read/write access to staged data and error logs due to predictable bucket naming. Organizations utilizing affected versions prior to April 27, 2026, should prioritize this issue to ensure their data remains secure, although no immediate action is required since the vulnerability has been patched.
Original NVD Description
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This vulnerability was patched and no customer action is needed.