Improper Authorization and Security-Boundary Bypass in Google BigQuery Component
CVE-2026-14538
5.7MEDIUM
What is CVE-2026-14538?
An improper authorization and security-boundary bypass vulnerability exists in the bigquery-execute-sql tool of Google mcp-toolbox versions 0.16.1 through 1.4.0. This flaw permits authenticated attackers to circumvent validation checks performed by allowedDatasets due to a fail-open logic error in the toolbox. When using the BigQuery dry-run API, if an empty array is returned, the toolbox fails to enforce dataset restrictions. As a result, attackers can exploit this weakness to access structural DDL schemas for datasets that should be explicitly excluded and retrieve downstream data through EXTERNAL_QUERY connections.
Affected Version(s)
mcp-toolbox 0.16.1 <= 1.4.0