{"id":"CVE-2026-19485","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-19485","summary":"A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker…","details":"A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names.\n\n\n\nThis vulnerability was patched and no customer action is needed.","published":"2026-08-26T19:16:49.157","modified":"2026-08-26T19:16:49.157","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-26T19:16:49.157"}}