CVE 9.1 CRITICAL

Information Disclosure via Bucket Squatting in Google Cloud Agentspace._CVE-2026-1727

9.1 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:L/U:Clear

Description

The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and temporary staging during data imports from GCS and Cloud SQL. This predictability allowed an attacker to engage in "bucket squatting" by establishing these buckets before a victim's initial use.

All versions after December 12th, 2025 have been updated to protect from this vulnerability. No user action is required for this.

AI Analysis

Information disclosure vulnerability via bucket squatting in Google Cloud Agentspace, allowing attackers to access sensitive information due to predictable Google Cloud Storage bucket names.

Basic Information

ID CVE-2026-1727
Source GoogleCloud
Published Feb 6, 2026 at 21:44

Affected Product

Vendor Google Cloud
Product Gemini Enterprise (formerly Agentspace)
Affected Versions Google Cloud Gemini Enterprise (formerly Agentspace) 0

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor Google Cloud
Product Gemini Enterprise (formerly Agentspace)
Version All versions before December 12th, 2025

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.