---
id: CVE-2026-19407
title: >-
  Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for
  Python versions prior to 1.166.1 allows an attacker to achieve Remote Code
  Execution (RCE) and tenant-project token theft.
summary: >-
  Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for
  Python versions prior to 1.166.1 allows an attacker to achieve Remote Code
  Execution (RCE) and tenant-project token theft.
severity: high
cvss: 7.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Clear'
cwe:
  - CWE-330
vendor: Google Cloud
product: Gemini Enterprise Agent Platform SDK for Python
affected:
  - gemini_enterprise_agent_platform_sdk_for_python >= 1.16.0 < 1.165.1
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:04.443'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19407'
references:
  - url: >-
      https://docs.cloud.google.com/gemini-enterprise-agent-platform/release-notes#March_31_2026
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-21T18:43:33.069564Z'
cvssSource: cna
epss: 0.00521
epssPercentile: 0.43062
ingestedAt: '2026-09-15T15:39:12.906Z'
---

## Overview

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
