Default Vertex AI Agent Permissions Expose Cloud Data

Palo Alto Networks Unit 42 found Vertex AI's default Per-Project, Per-Product Service Agent (P4SA) permissions are overly broad. A deployed Vertex AI agent can call Google's metadata service and expose the service agent's credentials, the hosting project ID, the agent identity, and the host scopes. Unit 42 used those credentials to move into the customer project and read all Google Cloud Storage buckets, turning a deployed agent into a potential insider threat.

Part of the PlainSec briefing for 2026-04-01

Sources