mcp-toolbox: authentication bypass
CriticalCVE-2026-11718 · Published Jun 18, 2026 · updated Jun 25, 2026
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, the subsequent claim-checking logic (validateClaims) evaluates the issuer condition as if a.issuer != "" && iss != "". If the external OAuth provider's introspection response omits the optional iss (issuer) field completely, the variable iss defaults to an empty string. This causes the conditional block to evaluate to false and be skipped silently. Consequently, the application accepts tokens issued by unauthorized or unintended third-party identity providers.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/googleapis/mcp-toolbox Go | < 1.4.0 | 1.4.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2026-11718, GO-2026-5706
More mcp-toolbox advisories
All mcp-toolbox| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 29 | MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints | Critical9.1 | 1.3.0 |
| Jun 18 | MCP Toolbox for Databases: authenticated authorization bypass | High | 1.4.0 |
| Jun 18 | mcp-toolbox: authentication bypass | Critical | 1.4.0 |
| Jun 13 | MCP Toolbox for Databases has an Origin Validation Error | Critical | 0.25.0 |
| May 28 | MCP Toolbox for Databases vulnerable to DNS rebinding attacks | Critical | 1.2.0 |