Google Mcp Toolbox For Databases — known CVE vulnerabilities
Every CVE whose affected-product data names Google Mcp Toolbox For Databases, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (9)
CVE-2026-14537 — CVSS 9.8 (critical): Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an…
CVE-2026-11718 — CVSS 9.1 (critical): An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox…
CVE-2026-11720 — CVSS 9.1 (critical): A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests…
CVE-2026-11717 — CVSS 9.1 (critical): An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox…
CVE-2026-11719 — CVSS 8.1 (high): An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older…
CVE-2026-14538 — CVSS 7.7 (high): An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox…
CVE-2026-14539 — CVSS 7.5 (high): An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including…
CVE-2026-14541 — CVSS 7.5 (high): An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version…
CVE-2026-14540 — CVSS 6.1 (medium): A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions…