CVE-2026-14537
Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.
| CWE | CWE-863 |
| Vendor | |
| Product | mcp-toolbox |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for google mcp-toolbox
Be the first to know when new unknown vulnerabilities affecting google mcp-toolbox are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google / mcp-toolbox
1.3.0 v1.4.0
References
Credits
HE WEI (ใฎใซใฏ) ๐ David Carliez