A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names.
This vulnerability was patched and no customer action is needed.
Attack Parameters
Impact Assessment
CVSS Vector v4.0