PT-2026-66667 · Google+1 · Mcp-Toolbox+1

·

CVE-2026-14541

·

Published

2026-07-31

·

Updated

2026-08-08

CVSS v4.0

8.0

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Google mcp-toolbox version 1.4.0
Description An authentication bypass and audience confusion issue exists in the Google OAuth provider component. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation. This allows the toolbox to accept any valid Google OAuth access token, including those created for unrelated ecosystem applications, which may grant unauthorized clients access to protected tools and data backends.
Recommendations Explicitly define the audience or clientId when initializing the Google authService with mcpEnabled: true for version 1.4.0.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14541

Affected Products

Mcp-Toolbox
Mcp Toolbox For Databases