CVE-2026-19485EPSS p12.1%
CVE-2026-19485CVE-2026-19485
Description
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names.
This vulnerability was patched and no customer action is needed.
Scoring
| EPSS | 0.23% probability of exploitation · percentile 12.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-31 |