Google mcp-toolbox 1.4.0: Auth Bypass & Audience Confusion in OAuth Provider
CVE-2026-14541 Published on July 31, 2026

Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access tokeneven those minted for unrelated ecosystem applicationsgranting unauthorized clients access to protected tools and data backends.

NVD

Weakness Type

What is an authentification Vulnerability?

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE-2026-14541 has been classified to as an authentification vulnerability or weakness.


Affected Versions

Google mcp-toolbox Version 1.4.0 is affected by CVE-2026-14541