CVE Database
/

CVE-2026-4810

Back to search

CVE-2026-4810

Published: Apr 13, 2026

Modified: Apr 13, 2026

PUBLISHED

Description

A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance. This vulnerability was patched in versions 1.28.1 and 2.0.0a2. Customers need to redeploy the upgraded ADK to their production environments. In addition, if they are running ADK Web locally, they also need to upgrade their local instance.

VendorProductVersions

Google Cloud

Agent Development Kit (ADK)

affected
1.7.0 - < 1.28.1
affected
2.0.0a1 - < 2.0.0a2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-4810 - Security Vulnerability | QwikSec