NONE · 0

CVE-2026-19407

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Vulnerability Description

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-19407?

CVE-2026-19407 is a documented vulnerability. Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

How severe is CVE-2026-19407?

CVSS scoring is not yet available for CVE-2026-19407. Check NVD for updates.

Is there a patch for CVE-2026-19407?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.