What is CVE-2026-14537?
An incorrect authorization vulnerability in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via direct HTTP API requests to legacy endpoints when --enable-api is used. Immediate update to the latest version is recommended to prevent unauthorized tool invocation on affected systems.
Azərbaycanca: Google mcp-toolbox-un v1.3.0 və v1.4.0 versiyalarında “scopeRequired” qorunan alətlər üçün birbaşa HTTP API vasitəsilə autentifikasiya olmadan icazəsiz alət çağırışına imkan verən səhv avtorizasiya zəifliyi aşkarlanıb. Təsirə məruz qalan sistemlərdə istismarın qarşısını almaq üçün dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Google
FAQ2
Which versions of Google mcp-toolbox are affected by CVE-2026-14537?
This vulnerability affects only versions v1.3.0 and v1.4.0 of Google mcp-toolbox.
How can one mitigate CVE-2026-14537?
Immediate update to the latest version is recommended to prevent exploitation on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.