PT-2026-88902 · Google Cloud · Agent Development Kit (Adk) For Python

·

CVE-2026-79696

·

Published

2026-09-09

·

Updated

2026-09-11

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Amber
🚨 Google disclosed a CVSS 10.0 vulnerability in ADK for Python today.
The fixed version shipped 27 days ago.
CVE-2026-79696 affects specific conditions:
🔹 ADK for Python 2.0.0 through 2.6.0 🔹 The adk web development interface 🔹 Environments where pytest is installed 🔹 Network access to the affected path
Google advises upgrading to version 2.7.0 or later and keeping adk web off the network.
An inventory result containing “Google ADK” does not prove exposure. Teams need to check the running interpreter, deployed package version, listening address and actual network route.
The main lesson is that agent security starts before the model. Development interfaces and configuration loaders can carry host-level authority.
#GoogleADK #CVE #AISecurity #AgentSecurity #ApplicationSecurity #DevSecOps #CyberSecurity

Fix

RCE

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79696

Affected Products

Agent Development Kit (Adk) For Python