---
cve: "CVE-2026-79696"
severity: "CRITICAL"
cvss: 10.0
epss: "0.7%"
vendor: "Google Cloud"
kev: false
exploited: false
published: "2026-09-09 09:17:11"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-04T09:07:28+02:00"
---

# CVE-2026-79696

> 10.0 CRITICAL · 🧪 PoC

## Beschreibung

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Amber
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- a5791dab0b1aeae88caab31ca6951653dcdbba8b (Commit)
- a16f6da3314b8dcd9925884cd6fc7fc9ffdd570d (Commit)

## Referenzen

- <https://github.com/google/adk-python/releases/tag/v2.7.0>
- <https://github.com/google/adk-python/commit/a16f6da3314b8dcd9925884cd6fc7fc9ffdd570d>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-79696) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
