CVE-2026-14537
8.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Summary
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the –enable-api flag is active.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mcp-toolbox | 1.3.0 | affected | |
| mcp-toolbox | v1.4.0 | affected |
Weaknesses
- CWE-863: CWE-863 (Incorrect Authorization)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.