logo

Google’s Vertex AI Vulnerability Enables Low-Privileged Users to Gain Service Agent Roles

ID: 6e2915a9-f3ea-5783-acad-343e8579ae89

STIX ID: report--6e2915a9-f3ea-5783-acad-343e8579ae89

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-17

Date Updated: 2026-04-21

Author: Guru Baran

...
...

XM Cyber and related reporting disclose default-configuration vulnerabilities in Google Vertex AI that permit privilege escalation through two paths: a malicious tool call in the Reasoning Engine (leading to RCE and theft of the Reasoning Engine Service Agent token) and insecure default access on Ray head nodes (viewer access enabling a root shell and theft of the Custom Code Service Agent token). Successful exploitation can expose LLM data, chats, and give read/write access to Cloud Storage and BigQuery; recommended mitigations include revoking unnecessary Service Agent permissions, disabling head node shells, validating staged tool code, and monitoring metadata access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.