Google CloudCVE-2026-79696
Google Cloud Agent Development Kit (ADK) for Python: code injection
Critical10.0CVE-2026-79696 · Published Sep 9, 2026
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Agent Development Kit (ADK) for Python Product | >= 2.0.0, < 2.7.0 | 2.7.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-184
More Google Cloud advisories
All Google Cloud| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Google Cloud Gemini Enterprise Agent Platform SDK: remote code execution | High7.7 | 1.165.1 |
| Sep 11 | Google Cloud Gemini Enterprise: server-side request forgery | High8.7 | 2026-06-01 |
| Sep 10 | Google Cloud Gemini CLI: code execution | High7.7 | 0.39.1 |
| Sep 4 | Google Cloud Agent Development Kit (ADK): path traversal | High8.7 | 1.22.0 |
| Sep 4 | Google Cloud Integration Connectors: missing authorization | High8.5 | 2025-12-11 |
| Aug 31 | Google Cloud Build: improper authorization | Critical9.4 | 2026-06-24 |