CVE-2026-18236 – Google ADK

CVSS 9.3 CRITICAL Critical - Same Day Deployment

“Trust in agent actions depends on verifying every approval, not just receiving one.”

Google has released a security update for the Agent Development Kit (ADK) to address a critical vulnerability in the tool confirmation process. The flaw allows continuation forgery in tool confirmations, enabling an attacker who can manipulate or inject events into the session history to execute unauthorized tools. The issue stems from insufficient validation of tool registration, confirmation requirements, and confirmation arguments. The CVSS score is 9.3, which is Critical severity.

The update strengthens validation of tool confirmation workflows by ensuring that confirmation requests are properly associated with the executing agent and the original tool invocation. No verified public proof-of-concept code or real-world exploitation has been confirmed for this vulnerability.

Key Details

CWE Classification
CWE-863
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.