CVE-2026-4810 is a code injection and missing authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 through 1.28.1, and 2.0.0a1 through 2.0.0a2, affecting Python open-source deployments, Cloud Run, and Google Kubernetes Engine (GKE) environments. This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected ADK servers, representing a critical integrity and confidentiality threat. The vulnerability combines code injection flaws with missing authentication controls, creating an unauthenticated attack vector with likely low complexity requirements. The flaw enables remote code execution, which presents severe potential impact including unauthorized system access, data exfiltration, and service disruption. Organizations must immediately redeploy patched versions 1.28.1 or 2.0.0a2 to production environments, including local ADK Web instances. There are no indicators of active exploitation in public CVE lists, and the vulnerability is not tracked on the Known Exploited Vulnerabilities (KEV) catalog. However, the FAUCET Risk Score of 53.0 out of 100 and EPSS score of 0.00145 suggest moderate practical risk requiring prioritized remediation. Community attention remains low at present, but the unauthenticated remote code execution capability warrants urgent patching regardless of current exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Google Cloud | Agent Development Kit (ADK) | >= 1.7.0, < 1.28.1, >= 2.0.0a1, < 2.0.0a2CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.