CVE-2026-2473High▾ TwilightGoogle Cloud Vertex AI has a a vulnerability involving predictable bucket naming
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.4%
Last analysed / modified upstream
0.4% → 0.5%
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting).
This vulnerability was patched and no customer action is needed.
google-cloud-aiplatform >= 1.21.0, < 1.133.0Upgrade to a patched release:
google-cloud-aiplatform 1.133.0Connected by shared product, vendor, weakness, or advisory.