CVE-2026-4810Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance. This vulnerability was patched in versions 1.28.1 and 2.0.0a2. Customers need to redeploy the upgraded ADK to their production environments. In addition, if they are running ADK Web locally, they also need to upgrade their local instance.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-13); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-13: 4Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-13: 4Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 104-1304-1404-15
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-134
Disclosure3Patch1
2026-04-141
Patch1
2026-04-151
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    Google ADK (CVE-2026-4810) faces a critical 9.3 CVSS RCE flaw. Unauthenticated attackers can hijack AI agents on GKE & Cloud Run. Update and redeploy now! #GoogleADK #AISecurity #RCE #CyberSecurity #GeminiAI #CloudSecurity #InfoSec https://securityonline.info/google-adk-vulnerability-cve-2026-4810-rce-fix/ https://t.co/YHL2Bn46pB

    Post summary

    The tweet announces a critical RCE vulnerability (CVE‑2026‑4810) in Google ADK with a 9.3 CVSS score and urges immediate patching, but no PoC or exploit details are provided.

    00061481
    12.3K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4810: Remote Code Ex... Unauthenticated RCE with 9.3 CVSS in Google's ADK—every Python/GKE deployment is a sitting duck until redeployed #GoogleADK #RCE #Critical. https://zerodaysignal.com/vulnerability/CVE-2026-4810 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new critical remote-code execution vulnerability (CVE‑2026‑4810) has been disclosed in Google’s ADK, scoring 9.3 CVSS and affecting all Python/GKE deployments until redeployed.

    00011128
    217 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical code injection and missing authentication vulnerability (CVE-2026-4810) affects `Google ADK`. Assess exposure and await vendor guidance. #Infosec #CodeInjection #AuthBypass https://www.pulsepatch.io/posts/cve-2026-4810-google-adk-code-injection-auth-bypass

    Post summary

    The tweet announces a new critical code injection and authentication bypass vulnerability (CVE‑2026‑4810) affecting Google ADK, urging stakeholders to assess exposure and wait for vendor guidance.

    0000065
    12 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4810 A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS… https://www.cve.org/CVERecord?id=CVE-2026-4810

    Post summary

    The CVE-2026-4810 describes a code injection and missing authentication flaw in Google ADK for Python, affecting releases 1.7.0 through 1.28.1; no PoC, exploit, active use, patch, or denial of validity is mentioned.

    00000122
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4810 Remote Code Execution in Google Agent Development Kit Versions 1.7.0 Through 2.0.0a2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4810

    Post summary

    The post reports a newly disclosed remote code execution vulnerability affecting Google Agent Development Kit versions 1.7.0–2.0.0a2.

    0000052
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-4810: CRITICAL] Vulnerabilities in Google Agent Development Kit enables remote attacks to execute malicious code on servers. Users must update to patched versions 1.28.1 & 2.0.0a2 to secure systems.#cve,CVE-2026-4810,#cybersecurity https://cvefind.com/CVE-2026-4810

    Post summary

    A critical vulnerability in Google Agent Development Kit is announced, with specific patched versions advised, but no PoC, exploit, or active exploitation claim is present.

    0000070
    620 followersView on X

Explore more