๐Ÿ” CVE Alert

CVE-2026-14537

UNKNOWN 0.0

Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.

CWE CWE-863
Vendor google
Product mcp-toolbox
Ecosystems
Industries
Technology
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for google mcp-toolbox

Be the first to know when new unknown vulnerabilities affecting google mcp-toolbox are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google / mcp-toolbox
1.3.0 v1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/googleapis/mcp-toolbox/pull/3435

Credits

HE WEI (ใ‚ฎใ‚ซใ‚ฏ) ๐Ÿ” David Carliez