CVE-2026-14537Patch(google / mcp_toolbox_for_databases)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google mcp_toolbox_for_databases systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_toolbox_for_databases

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
mcp_toolbox_for_databases

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-24: 2Mentions · 2026-08-25: 1Mentions · 2026-09-17: 1Patch / Workaround · 2026-08-24: 2Technical Details · 2026-08-24: 2Technical Details · 2026-09-17: 108-2408-2509-17
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-242
Patch2
2026-08-251
Disclosure1
2026-09-171
Disclosure1
Full discourse4 posts
  • 7h3h4ckv157@7h3h4ckv157
    Disclosure

    CVE-2026-14537: Understanding the Google MCP Toolbox Authorization Flaw Credit/Author: HE WEI (ギカク) Source: https://gikaku.net/2026/08/25/cve-2026-14537/

    Post summary

    The provided text refers to a blog post that discloses CVE‑2026‑14537, a Google MCP Toolbox authorization flaw, but does not include technical details, PoC, or patch information.

    06016112.5K
    57.1K followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    Google mcp-toolbox の v1.3.0 と v1.4.0 に、レガシーHTTP API経由で認可を未認証で回避できる欠陥がありました。修正は v1.5.0 で、両方を有効にした構成は起動しなくなります。該当条件を整理しました。 https://cve.autoarticles.net/cve/CVE-2026-14537

    Post summary

    CVE-2026-14537 exposed an unauthenticated authorization bypass in Google mcp‑toolbox v1.3.0/v1.4.0 via a legacy HTTP API; the issue is fixed in v1.5.0, which disables the vulnerable configuration.

    0001065
    562 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-14537: Google MCP Toolbox Authorization Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04xPnNj0

    Post summary

    The text announces CVE-2026-14537 as an authorization bypass vulnerability in Google MCP Toolbox, offering brief technical details and general guidance without mentioning PoC, exploits, or patches.

    0000040
    34 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    新しい入口に認可を足しても、古い入口が残っていれば素通しになります。mcp-toolbox の認可回避を、実際のパッチを読んで整理しました。修正が穴埋めではなく起動時チェックだった理由と、手元のコードで同じ形を探す方法まで書いています。 https://blog.hashito.biz/2026/08/24/mcp-toolbox-cve-2026-14537-legacy-endpoint-authz-bypass/

    Post summary

    The blog post reviews the CVE‑2026‑14537 authorization bypass in mcp‑toolbox, explains how the patch fixes the legacy endpoint issue, and offers guidance on detecting similar patterns in source code.

    0000054
    562 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglemcp_toolbox_for_databases1.3.0--
Appgooglemcp_toolbox_for_databases1.4.0--

Explore more