CVE-2026-2473Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets (Bucket Squatting). This vulnerability was patched and no customer action is needed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-340

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • False Positive: 1 classified signal
  • Peaked 6d ago at 1 mentions (2026-02-20); latest day: 1
  • 7 total mentions across 7 days

Deep dive

Activity timeline7 mentions / 7d
00111Mentions · 2026-02-20: 1Mentions · 2026-03-01: 1Mentions · 2026-04-20: 1Mentions · 2026-06-16: 1Mentions · 2026-06-18: 1Mentions · 2026-06-23: 1Mentions · 2026-07-10: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-01: 1Technical Details · 2026-04-20: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 1Technical Details · 2026-07-10: 102-2003-0104-2006-1606-1806-2307-10
Signal classification4 categories
Disclosure
457.1%
Patch
114.3%
False Positive
114.3%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-201
Disclosure1
2026-03-011
Disclosure1
2026-04-201
Disclosure1
2026-06-161
Patch1
2026-06-181
Disclosure1
2026-06-231
False Positive1
2026-07-101
General1
Full discourse7 posts
  • Araceli González Vázquez 💢@Araceli_ENTHUMN
    False Positive

    ... la interpretación del Reglamento (UE) 2023/1115 es espuria y, por lo tanto, solicitamos que se retire del curso legal la Resolución CVE-2026-2473 del Gobierno de Cantabria del PP de Buruaga.

    Post summary

    The text debunks the validity of the Resolution CVE‑2026‑2473, claiming it is spurious, with no other actionable information about the vulnerability.

    11070100
    2.4K followersView on X
  • OmerAF@omer_asfu
    Disclosure

    I found this squatting pattern recurring across three major GCP services: • VertexSquat (CVE-2026-2473): Full RCE in Vertex AI. • GeminiSquat (CVE-2026-1727): Gemini Enterprise. • MountSquat: Takeover of Cloud Run mount volumes.

    Post summary

    The post identifies a pattern of vacated security reviews across Google Cloud services, highlighting CVE-2026-2473 as a full RCE in Vertex AI, while noting related CVEs without providing exploit, mitigation, or PoC details.

    120421.0K
    655 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    General

    TRC analysis shows attackers exploiting predictable bucket naming patterns to silently redirect organizational data streams to attacker-controlled storage. CVE-2026-2473 and CVE-2026-1727 demonstrate how misconfigured cloud storage enables privilege escalation and lateral movement across cloud resources. Runtime segmentation could help contain post-compromise activity. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/threatsday-cloud-bucket-hijacking-2026

    Post summary

    The analysis details how predictable bucket naming patterns can lead to misconfigured cloud storage, referencing CVE-2026-2473 and CVE-2026-1727, but offers no PoC, exploit code, patches, or evidence of active exploitation.

    1000068
    1.9K followersView on X
  • Daily Security Review@securitydailyr
    Disclosure

    Unit 42 disclosed CVE-2026-2473 in Google Cloud Vertex AI SDK — bucket squatting + Pickle deserialization enables cross-tenant RCE with zero access to the victim’s GCP project. Patched in google-cloud-aiplatform v1.148.0. https://dailysecurityreview.com/resources/cve-2026-2473-vertex-ai-sdk-pickle-attack-enables-cross-tenant-rce/ #CyberSecu https://t.co/fBwmz33Pux

    Post summary

    Unit 42 disclosed CVE‑2026‑2473, a bucket squatting and Pickle deserialization flaw in Google Cloud Vertex AI SDK that enables cross‑tenant RCE without project access, and the issue is patched in google‑cloud‑aiplatform v1.148.0.

    01000104
    119 followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Patch

    🚨 UPDATE — Vertex AI bucket squatting: This isn't a one-off. Focal Security separately disclosed THREE Google Cloud bucket squatting flaws this year — GeminiSquat (CVE-2026-1727) in Gemini Enterprise, MountSquat in Cloud Run, and VertexSquat (CVE-2026-2473) in Vertex AI Experiments. All three: no credentials needed, cross-tenant code execution. No CVE has been assigned to the new 'Pickle in the Middle' flaw yet. But the pattern is clear: Google Cloud's predictable bucket naming convention is a systemic architectural problem, not a one-time bug. Check your google-cloud-aiplatform version in notebooks, CI jobs, and training pipelines — not just production. Update to v1.148.0 now. 👇 https://thehackernews.com/2026/06/google-vertex-ai-sdk-flaw-let-attackers.html

    Post summary

    Three Google Cloud bucket squatting vulnerabilities enabled cross‑tenant code execution without credentials; users are urged to update to v1.148.0.

    0000063
    84 followersView on X
  • Nikhil Raj@iam_nikhil_raj
    Disclosure

    Vertex AI Security Alert CVE-2026-2473: Predictable bucket naming in Vertex AI Experiments could allow cross-tenant RCE & model theft (Bucket Squatting). Official Google Cloud Bulletin: NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2026-2473 #VertexAI #GoogleCloud #CloudSecurity #CVE #DevSecOps

    Post summary

    Google Cloud has issued a security alert for CVE-2026-2473, noting that predictable bucket naming in Vertex AI Experiments could lead to cross‑tenant remote code execution and model theft.

    0000060
  • CVE@CVEnew
    Disclosure

    CVE-2026-2473 Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an un… https://www.cve.org/CVERecord?id=CVE-2026-2473

    Post summary

    The text provides a brief disclosure of a predictable bucket naming issue in Vertex AI Experiments across specific versions, highlighting a potential security risk.

    0000094
    56.4K followersView on X

Explore more