Description
A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the target tool was registered to the executing agent, did not validate if the tool actually required confirmation, and did not match the confirmation arguments against the original tool call event in the history.
Published: 2026-07-29
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Google Agent Development Kit contains a missing authorization check that allows an attacker, who can inject or manipulate events in a session history, to forge tool confirmation responses. This enables the execution of unauthorized tools, granting the attacker the privileges of the executing agent and potentially compromising confidentiality, integrity, and availability. The weakness is a type of Missing Authorization (CWE‑863).

Affected Systems

Google's Agent Development Kit (ADK) is affected. No specific affected versions were provided in the advisory, so any deployment of ADK prior to a security update may be vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 9.3, indicating a high risk if exploited. The EPSS score is less than 1%, suggesting that exploitation evidence is currently rare but the low likelihood does not mitigate the severity. The issue is not listed in the CISA KEV catalog. An attacker who can compromise or otherwise control session history can execute arbitrary tools by forging confirmations, so the attack vector is likely through any component that accepts or allows manipulation of session history. Organizations should consider the potential impact and plan remediation accordingly.

Generated by OpenCVE AI on August 3, 2026 at 13:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Google ADK update that fixes tool confirmation forgery.
  • Limit or audit session history manipulation to trusted entities only.
  • Modify the ADK configuration or code to validate tool registration, confirmation requirement, and argument consistency before executing tools.

Generated by OpenCVE AI on August 3, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud agent Development Kit (adk)
Vendors & Products Google Cloud
Google Cloud agent Development Kit (adk)

Wed, 29 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the target tool was registered to the executing agent, did not validate if the tool actually required confirmation, and did not match the confirmation arguments against the original tool call event in the history.
Title Google-ADK Continuation Forgery
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Google Cloud Agent Development Kit (adk)
cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2026-07-29T18:08:58.347Z

Reserved: 2026-07-29T13:03:32.303Z

Link: CVE-2026-18236

cve-icon Vulnrichment

Updated: 2026-07-29T18:08:44.151Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T18:16:52.140

Modified: 2026-07-30T14:15:31.167

Link: CVE-2026-18236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:15:05Z

Weaknesses