What is CVE-2026-14538?
CVE-2026-14538 is an improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool of Google mcp-toolbox versions 0.16.1 through 1.4.0. It allows an authenticated attacker to bypass allowedDatasets validation by exploiting the BigQuery dry-run API. Upgrading to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-14538 Google mcp-toolbox-un bigquery-execute-sql alətində aşkarlanmış səhv avtorizasiya və təhlükəsizlik sərhədini keçmə zəifliyidir. 0.16.1-dən 1.4.0-a qədər versiyalara təsir edir və autentifikasiya olunmuş hücumçuya BigQuery dry-run API yoxlamalarını manipulyasiya edərək allowedDatasets məhdudiyyətlərini keçməyə imkan verir. Dərhal ən son versiyaya yenilənmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Google
FAQ2
Which Google product is affected by CVE-2026-14538 and what versions are at risk?
The bigquery-execute-sql tool of Google mcp-toolbox versions 0.16.1 through 1.4.0 is affected.
How to protect against CVE-2026-14538?
Upgrading to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.