CVE-2026-14537: CWE-863 (Incorrect Authorization) in Google mcp-toolbox
CVE-2026-14537 is a high-severity incorrect authorization vulnerability in Google mcp-toolbox versions 1.3.0 and 1.4.0. It allows unauthenticated attackers to invoke tools that should be protected by the scopeRequired feature by sending requests through legacy HTTP endpoints when the --enable-api flag is enabled.
AI Analysis
Technical Summary
This vulnerability (CWE-863) exists in the direct HTTP API tool invocation endpoint of Google mcp-toolbox versions 1.3.0 and 1.4.0. When the --enable-api flag is active, the legacy HTTP endpoints do not properly enforce authorization checks, allowing unauthenticated attackers to invoke protected tools. This bypass of intended authorization controls can lead to unauthorized access to sensitive functionality.
Potential Impact
An unauthenticated attacker can invoke tools that are intended to be protected by authorization scopes, potentially leading to unauthorized actions or access within the mcp-toolbox environment. The CVSS 4.0 score of 8.1 reflects high impact due to network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to disable the --enable-api flag or avoid using legacy HTTP endpoints for tool invocation to prevent unauthorized access.
CVE-2026-14537: CWE-863 (Incorrect Authorization) in Google mcp-toolbox
Description
CVE-2026-14537 is a high-severity incorrect authorization vulnerability in Google mcp-toolbox versions 1.3.0 and 1.4.0. It allows unauthenticated attackers to invoke tools that should be protected by the scopeRequired feature by sending requests through legacy HTTP endpoints when the --enable-api flag is enabled.
CVSS v4.0
Score 8.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-863) exists in the direct HTTP API tool invocation endpoint of Google mcp-toolbox versions 1.3.0 and 1.4.0. When the --enable-api flag is active, the legacy HTTP endpoints do not properly enforce authorization checks, allowing unauthenticated attackers to invoke protected tools. This bypass of intended authorization controls can lead to unauthorized access to sensitive functionality.
Potential Impact
An unauthenticated attacker can invoke tools that are intended to be protected by authorization scopes, potentially leading to unauthorized actions or access within the mcp-toolbox environment. The CVSS 4.0 score of 8.1 reflects high impact due to network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to disable the --enable-api flag or avoid using legacy HTTP endpoints for tool invocation to prevent unauthorized access.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Date Reserved
- 2026-07-03T01:40:43.351Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6bffe69c2644c7f8215518
Added to database: 07/31/2026, 01:52:38 UTC
Last enriched: 08/07/2026, 14:47:52 UTC
Last updated: 09/10/2026, 19:38:45 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.