PT-2026-82243 · Google · Bigquery+1
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/U:Clear |
Name of the Vulnerable Software and Affected Versions
Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27
Description
A Predictable Resource Name issue exists in the BigQuery Import Staging component on Google Cloud Platform. An attacker who knows the victim's project number can exploit predictable bucket names to gain read and write access to staged data and error logs.
Recommendations
No customer action is needed as the issue has been patched.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigquery
Vertex Ai Search For Commerce