Executive Summary
In January 2026, security researchers identified critical privilege escalation vulnerabilities in Google Cloud's Vertex AI platform. These flaws allowed low-privileged users to gain high-privilege Service Agent roles, potentially leading to unauthorized access to sensitive data and resources. The vulnerabilities were found in the Vertex AI Agent Engine and Ray on Vertex AI, where default configurations enabled attackers to escalate permissions from 'Viewer' to project-wide access. Google acknowledged that the services were 'working as intended,' indicating that these risks persist in default deployments. (cyberpress.org)
This incident underscores the importance of scrutinizing default configurations in cloud services, as they can inadvertently expose organizations to significant security risks. The ability for low-privileged users to escalate their permissions highlights the need for robust access controls and continuous monitoring to prevent unauthorized access and potential data breaches.
Why This Matters Now
The persistence of these vulnerabilities in default deployments of Vertex AI emphasizes the urgent need for organizations to review and secure their cloud configurations. As cloud adoption accelerates, ensuring that default settings do not expose systems to privilege escalation attacks is critical to maintaining data security and compliance.
Attack Path Analysis
An overprivileged AI agent in Google Cloud's Vertex AI was exploited due to cloud misconfigurations, allowing unauthorized access. The adversary escalated privileges by modifying IAM roles and policies. They conducted lateral movement by discovering and accessing additional cloud services. Command and control was established through persistent access mechanisms. Sensitive data was exfiltrated to external destinations. The attack culminated in significant data loss and operational disruption.
Kill Chain Progression
Initial Compromise
Description
Exploitation of overprivileged AI agent in Vertex AI due to cloud misconfigurations.
Related CVEs
CVE-2026-2473
CVSS 7.7Predictable bucket naming in Vertex AI Experiments allows unauthenticated remote attackers to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud Storage buckets.
Affected Products:
Google Vertex AI – 1.21.0 up to but not including 1.133.0
Exploit Status:
no public exploitCVE-2026-2244
CVSS 8.4A vulnerability in Google Cloud Vertex AI Workbench allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script.
Affected Products:
Google Vertex AI Workbench – 7/21/2025 to 01/30/2026
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Abuse Elevation Control Mechanism
Use Alternate Authentication Material
Impair Defenses
Modify Cloud Compute Infrastructure
Data from Cloud Storage
Transfer Data to Cloud Account
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Limit access to system components and cardholder data to only those individuals whose job requires such access.
Control ID: 7.2.1
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Governance and Administration
Control ID: 2.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
GCP Vertex AI cloud misconfigurations expose AI development platforms to overprivileged agent attacks, compromising software deployment pipelines and intellectual property.
Information Technology/IT
Cloud misconfiguration vulnerabilities in AI services create lateral movement risks across IT infrastructure, requiring enhanced zero trust segmentation controls.
Financial Services
Overprivileged AI agents threaten financial cloud environments, potentially violating regulatory compliance frameworks and enabling unauthorized data exfiltration attacks.
Health Care / Life Sciences
Vertex AI security blind spots expose healthcare AI applications to privilege escalation, threatening HIPAA compliance and patient data protection.
Sources
- Double Agents: Exposing Security Blind Spots in GCP Vertex AIhttps://unit42.paloaltonetworks.com/double-agents-vertex-ai/Verified
- NVD - CVE-2026-2473https://nvd.nist.gov/vuln/detail/CVE-2026-2473Verified
- NVD - CVE-2026-2244https://nvd.nist.gov/vuln/detail/CVE-2026-2244Verified
- ModeLeak: Privilege Escalation to LLM Model Exfiltration in Vertex AIhttps://unit42.paloaltonetworks.com/privilege-escalation-llm-model-exfil-vertex-ai/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to exploit overprivileged AI agents and move laterally within the cloud environment, thereby reducing the potential blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit overprivileged AI agents may have been constrained, reducing unauthorized access opportunities.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges by modifying IAM roles may have been limited, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the cloud environment may have been restricted, reducing access to additional services.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish persistent access may have been constrained, reducing long-term unauthorized presence.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data may have been limited, reducing data loss.
The overall impact of data loss and operational disruption may have been reduced, limiting the attack's severity.
Impact at a Glance
Affected Business Functions
- AI Model Training
- Data Storage
- Cloud Infrastructure Management
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of proprietary AI models and sensitive training data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
- • Utilize Multicloud Visibility & Control to monitor and manage cloud services, detecting anomalous activities.
- • Apply Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to suspicious behaviors in real-time.
- • Regularly audit and adjust IAM roles and policies to ensure minimal necessary privileges are granted.



