Incorrect Authorization Vulnerability in Google MCP-Toolbox
CVE-2026-14537
8.1HIGH
What is CVE-2026-14537?
An incorrect authorization vulnerability exists in the MCP-Toolbox, specifically within the direct HTTP API tool invocation endpoint. This flaw allows unauthenticated attackers to invoke tools that are typically secured by the 'scopeRequired' feature. By exploiting legacy HTTP endpoints while the '--enable-api' flag is activated, attackers can bypass intended access controls and potentially execute unauthorized operations.
Affected Version(s)
mcp-toolbox 1.3.0
mcp-toolbox v1.4.0