Description
A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to missing authorization. The attack can be launched remotely. Upgrading to version 1.3.0 is sufficient to resolve this issue. The name of the patch is e9a1abf9c90c02b16d17293afdc3cc2f555d63a6. The affected component should be upgraded.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Task Enumeration
Action: Patch
AI Analysis

Impact

A2aJava’s AuthorizationRequestHandlerDecorator.onListTasks method omits a proper authorization check, allowing a remote attacker to call the task‑listing endpoint without credentials. The missing control lets an adversary enumerate internal tasks, potentially exposing sensitive operational data and providing a foothold for further attacks. The weakness corresponds to the conditions restrictions and missing authorization weaknesses identified as CWE‑862 and CWE‑863.

Affected Systems

The vulnerable component is a2a-java version 1.2.0. Upgrading to release 1.3.0.Final applies the patch commit e9a1abf9c90c02b16d17293afdc3cc2f555d63a6, restoring proper authorization and eliminating the flaw. No other vendor or product versions are documented as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, and the missing authorization can be exploited to retrieve task information without authentication. Because the impact is limited to task enumeration rather than full system compromise, the overall risk is moderate but still requires timely patching.

Generated by OpenCVE AI on September 15, 2026 at 12:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade a2a-java to version 1.3.0.Final or later to apply the official patch that restores proper authorization.
  • Review existing role‑based access control rules for task‑listing endpoints to confirm that only users with the appropriate privileges can retrieve task information.
  • Enforce network segmentation or firewall rules to restrict external access to the task‑listing API, minimizing the potential impact of any undiscovered vulnerabilities.

Generated by OpenCVE AI on September 15, 2026 at 12:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to missing authorization. The attack can be launched remotely. Upgrading to version 1.3.0 is sufficient to resolve this issue. The name of the patch is e9a1abf9c90c02b16d17293afdc3cc2f555d63a6. The affected component should be upgraded.
Title a2aproject a2a-java AuthorizationRequestHandlerDecorator.java AuthorizationRequestHandlerDecorator.onListTasks authorization
First Time appeared A2aproject
A2aproject a2a-java
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:a2aproject:a2a-java:*:*:*:*:*:*:*:*
Vendors & Products A2aproject
A2aproject a2a-java
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

A2aproject A2a-java
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:55:18.224Z

Reserved: 2026-09-13T19:01:40.764Z

Link: CVE-2026-90820

cve-icon Vulnrichment

Updated: 2026-09-15T13:32:20.732Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T21:17:42.363

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:45:18Z

Weaknesses