CVE-2026-2473 describes a predictable bucket naming vulnerability in Google Cloud Vertex AI Experiments, affecting versions 1.21.0 up to (but not including) 1.133.0. An unauthenticated remote attacker could exploit this by pre-creating predictably named Cloud Storage buckets (bucket squatting). This high-severity vulnerability (CVSS 7.7) allowed for cross-tenant remote code execution, model theft, and data poisoning. Google has patched this issue, and no customer action is required; there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Google Cloud | Vertex AI Experiments | >= 1.21.0, < 1.133.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Feb 20, 2026Predictable bucket naming vulnerability in Google Cloud Vertex AI
Feb 20, 2026Predictable bucket naming vulnerability in Google Cloud Vertex AI Experiments