Skip to content
GoogleCVE-2026-18236

Google-ADK: improper authorization

Critical9.3CVE-2026-18236 · Published Jul 29, 2026 · updated Jul 30, 2026

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the target tool was registered to the executing agent, did not validate if the tool actually required confirmation, and did not match the confirmation arguments against the original tool call event in the history.

Google advisory

Affected versions

PackageAffectedFixed in
Google-ADK
Product
<= < 2.5.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More Google advisories

All Google
Advisory
Google Chrome: improper input validation
High8.3Jul 30
Google Chrome: protection mechanism failure
Medium4.2Jul 30
Google Chrome: use after free
High8.8Jul 30
Google Chrome: use after free
High8.3Jul 30
Google Chrome: remote attacker could potentially perform a sandbox escape
Critical9.6Jul 30
Google Chrome: use after free
High8.3Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.