Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4810

44
FAUCET Score

CVE-2026-4810 is a code injection and missing authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 through 1.28.1, and 2.0.0a1 through 2.0.0a2, affecting Python open-source deployments, Cloud Run, and Google Kubernetes Engine (GKE) environments. This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected ADK servers, representing a critical integrity and confidentiality threat. The vulnerability combines code injection flaws with missing authentication controls, creating an unauthenticated attack vector with likely low complexity requirements. The flaw enables remote code execution, which presents severe potential impact including unauthorized system access, data exfiltration, and service disruption. Organizations must immediately redeploy patched versions 1.28.1 or 2.0.0a2 to production environments, including local ADK Web instances. There are no indicators of active exploitation in public CVE lists, and the vulnerability is not tracked on the Known Exploited Vulnerabilities (KEV) catalog. However, the FAUCET Risk Score of 53.0 out of 100 and EPSS score of 0.00145 suggest moderate practical risk requiring prioritized remediation. Community attention remains low at present, but the unauthenticated remote code execution capability warrants urgent patching regardless of current exploitation status.

Impacted Technologies

VendorProductVersion(s)CPE
Google CloudAgent Development Kit (ADK)
>= 1.7.0, < 1.28.1, >= 2.0.0a1, < 2.0.0a2CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.82%
Probability of exploitation in next 30 days
EPSS Percentile
76.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Nuclei: CVE-2026-4810 · Apr 16, 2026
This CVE's current EPSS score of 0.0182 is in the 65th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: google-adkFixed in: 2.0.0a2
pippatch availablevia ghsa
Product: google-adkFixed in: 1.28.1

Vendor Advisories (1)

pipGHSA-rg7c-g689-fr3xcritical

Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerability

Apr 13, 2026

References

github.com / google/adk-python/blob/main/CHANGELOG.md