CVE-2026-14537

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.
References
Link Resource
https://github.com/googleapis/mcp-toolbox/pull/3435 Issue Tracking Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:mcp_toolbox_for_databases:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:google:mcp_toolbox_for_databases:1.4.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-31 02:16

Updated : 2026-08-08 00:25


NVD link : CVE-2026-14537

Mitre link : CVE-2026-14537

CVE.ORG link : CVE-2026-14537


JSON object : View

Products Affected

google

  • mcp_toolbox_for_databases
CWE
CWE-863

Incorrect Authorization