Google mcp-toolbox v1.3.0-1.4.0: Unauth HTTP API Tool Invocation
CVE-2026-14537 Published on July 31, 2026

Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.

NVD

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2026-14537 has been classified to as an AuthZ vulnerability or weakness.


Affected Versions

Google mcp-toolbox: