A vulnerability described as critical has been identified in Google Agent Development Kit up to 1.28.0/2.0.0a1. This impacts an unknown function. Executing a manipulation can lead to missing authentication.

The identification of this vulnerability is CVE-2026-4810. The attack may be launched remotely. There is no exploit available.

This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves. Upgrading the affected component is recommended.