logo

Google Cloud’s Vertex AI platform Vulnerability Allow Attackers to Access Sensitive Data

ID: 9fc46cea-7c9f-5fa0-9ec5-ac93d3de6f30

STIX ID: report--9fc46cea-7c9f-5fa0-9ec5-ac93d3de6f30

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-01

Date Updated: 2026-05-05

Author: Abinaya

...
...

Researchers found that Vertex AI Agent Engine’s default service agent permissions (P4SA) can expose service credentials from deployed agents, enabling attackers to pivot from the agent to consumer projects, read Cloud Storage, access Artifact Registry and proprietary images, and potentially achieve remote code execution by manipulating an insecure Python pickle file; Google worked with researchers to mitigate the issue and recommends using Bring Your Own Service Account to enforce least privilege.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.