What is CVE-2026-18236?
CVE-2026-18236 is a continuation forgery vulnerability in the Agent Development Kit (ADK) affecting tool confirmations. An attacker who can inject events into the session history may execute unauthorized tools by forging a tool confirmation response. Users of ADK should enforce strict session management and restrict event inputs from untrusted sources.
Azərbaycanca: CVE-2026-18236 Agent Development Kit (ADK)-də alət təsdiqləmələrində davam saxtakarlığı zəifliyidir. Sessiya tarixçəsinə hadisə inyeksiya edə bilən hücumçu, saxta tool confirmation cavabı ilə icazəsiz alətləri işə sala bilər. ADK istifadəçiləri sessiya idarəetməsini gücləndirməli və etibarsız mənbələrdən hadisə qəbulunu məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
How can an attacker exploiting CVE-2026-18236 execute unauthorized tools?
An attacker can inject events into the session history to forge a tool confirmation response.
What measures should Agent Development Kit users take to mitigate the risk of CVE-2026-18236?
Users should enforce strict session management and restrict event inputs from untrusted sources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.