A vulnerability was found in Google ADK up to 2.4.x. It has been classified as problematic. Impacted is an unknown function of the component Tool Confirmation. This manipulation causes improper authorization.

This vulnerability is registered as CVE-2026-18236. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.