---
id: CVE-2026-90820
title: A security vulnerability has been detected in a2aproject a2a-java 1.2.0
summary: >-
  A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The
  impacted element is the function
  AuthorizationRequestHandlerDecorator.onListTasks of the file
  server-common/src/main/java/org/a2aproject/sdk/server/requesthandl…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
  - CWE-863
vendor: a2aproject
product: a2a-java
affected:
  - a2a-java 1.2.0
published: '2026-09-14'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T14:37:14.523'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90820'
references:
  - url: 'https://github.com/a2aproject/a2a-java/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/a2aproject/a2a-java/commit/e9a1abf9c90c02b16d17293afdc3cc2f555d63a6
    label: cna@vuldb.com
  - url: 'https://github.com/a2aproject/a2a-java/pull/1038'
    label: cna@vuldb.com
  - url: 'https://github.com/a2aproject/a2a-java/releases/tag/v1.3.0.Final'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90820'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/925152'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403323'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403323/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T13:32:14.683925Z'
epss: 0.00394
epssPercentile: 0.30826
ingestedAt: '2026-09-14T21:15:17.559Z'
---

## Overview

A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to missing authorization. The attack can be launched remotely. Upgrading to version 1.3.0 is sufficient to resolve this issue. The name of the patch is e9a1abf9c90c02b16d17293afdc3cc2f555d63a6. The affected component should be upgraded.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
