Skip to content
GoogleCVE-2026-14538

Google mcp-toolbox: improper authorization

Medium5.7CVE-2026-14538 · Published Jul 31, 2026 · updated Aug 8, 2026

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a fail-open logic flaw, it bypasses validation when the API returns an empty array for specialized constructs. This allows the attacker to extract structural DDL schemas for explicitly excluded datasets via INFORMATION_SCHEMA, and access downstream federated row data via EXTERNAL_QUERY connections.

Google advisory

Affected versions

PackageAffectedFixed in
mcp-toolbox
Product
>= 0.16.1, <= 1.4.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-285, CWE-863

More Google advisories

All Google
Advisory
Google mcp-toolbox: authentication bypass
High8.0Jul 31
Google mcp-toolbox: server-side request forgery
High8.0Jul 31
Google mcp-toolbox: denial of service
Medium6.6Jul 31
Google mcp-toolbox: improper authorization
High8.1Jul 31
Google Chrome: spoofing
Medium4.3Jul 30
Google Chrome: remote attacker could bypass navigation restrictions
Medium6.5Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.