PT-2026-50661 · Unknown · Mcp Toolbox For Databases

·

CVE-2026-11719

·

Published

2026-06-18

·

Updated

2026-08-17

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MCP Toolbox for Databases (affected versions not specified)
Description An authenticated authorization bypass occurs due to missing scope enforcement in older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported versions (2025-06-18, 2025-03-26, and 2024-11-05) do not perform this check. An authenticated client with low-privilege tokens can bypass these restrictions and execute high-privilege tools by specifying an older protocol version in the MCP-Protocol-Version header or by omitting the header, which defaults the server to the 2024-11-05 handler.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11719
GHSA-5GF6-GC35-XJPC
GO-2026-5144
OPENSUSE-SU-2026:21483-1

Affected Products

Mcp Toolbox For Databases