Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-18236: Google-ADK Continuation Forgery: Unauthorized Tool Execution

CVE-2026-18236 · published 1 month ago
Summary

An attacker can trick Google-ADK into running unauthorized tools by manipulating session history. This can lead to malicious actions being taken without proper authorization. To stay safe, ensure you only use trusted and up-to-date versions of Google-ADK.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
google google-adk < 2.5.0
Original advisory text
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute...
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the target tool was registered to the executing agent, did not validate if the tool actually required confirmation, and did not match the confirmation arguments against the original tool call event in the history.
Severity
9.3 Critical
CVSS 4.0: 9.3 (NVD)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published29 Jul 2026
Updated27 Sep 2026
First seen29 Jul 2026
Sources
CVE-2026-18236 · MITRE
Track software like this
Free during beta