CVE-2026-90820 | a2aproject a2a-java 1.2.0 AuthorizationRequestHandlerDecorator.java AuthorizationRequestHandlerDecorator.onListTasks authorization (ID 1038)
A vulnerability labeled as problematic has been found in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-90820. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.