CVE-2026-14541 | Google mcp-toolbox 1.4.0 Google OAuth provider ValidateMCPAuth mcpEnabled/audience/clientId improper authorization

SecurityVulns

A vulnerability described as critical has been identified in Google mcp-toolbox 1.4.0. The affected element is the function ValidateMCPAuth of the component Google OAuth provider. The manipulation of the argument mcpEnabled/audience/clientId results in improper authorization.

This vulnerability is cataloged as CVE-2026-14541. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More