9.1
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:L/U:Clear
Description
The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and temporary staging during data imports from GCS and Cloud SQL. This predictability allowed an attacker to engage in "bucket squatting" by establishing these buckets before a victim's initial use.
All versions after December 12th, 2025 have been updated to protect from this vulnerability. No user action is required for this.
All versions after December 12th, 2025 have been updated to protect from this vulnerability. No user action is required for this.
AI Analysis
Information disclosure vulnerability via bucket squatting in Google Cloud Agentspace, allowing attackers to access sensitive information due to predictable Google Cloud Storage bucket names.
Basic Information
ID
CVE-2026-1727
Source
GoogleCloud
Published
Feb 6, 2026 at 21:44
Affected Product
Vendor
Google Cloud
Product
Gemini Enterprise (formerly Agentspace)
Affected Versions
Google Cloud Gemini Enterprise (formerly Agentspace) 0
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
Google Cloud
Product
Gemini Enterprise (formerly Agentspace)
Version
All versions before December 12th, 2025