---
id: CVE-2026-14537
title: >-
  Incorrect Authorization in the direct HTTP API tool invocation endpoint in
  Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated
  attacker to invoke tools protected by the scopeRequired feature via sending
  tool invocatio…
summary: >-
  Incorrect Authorization in the direct HTTP API tool invocation endpoint in
  Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated
  attacker to invoke tools protected by the scopeRequired feature via sending
  tool invocatio…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: google
product: mcp_toolbox_for_databases
affected:
  - mcp_toolbox_for_databases = 1.3.0
  - mcp_toolbox_for_databases = 1.4.0
published: '2026-07-31'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14537'
references:
  - url: 'https://github.com/googleapis/mcp-toolbox/pull/3435'
    label: cve-coordination@google.com
tags:
  - nvd
epss: 0.00216
epssPercentile: 0.12316
ingestedAt: '2026-08-08T14:22:57.078Z'
---

## Overview

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.

## Affected

- `mcp_toolbox_for_databases = 1.3.0`
- `mcp_toolbox_for_databases = 1.4.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
