{"id":"CVE-2026-14541","summary":"Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider","details":"An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.","modified":"2026-08-02T03:31:51.139043175Z","published":"2026-07-31T01:48:39.019Z","database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14541.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14541.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14541"},{"type":"FIX","url":"https://github.com/googleapis/mcp-toolbox/pull/3450"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/googleapis/mcp-toolbox","events":[{"introduced":"d67cfbe8ddca5a50c9577ea11feaf5c94d0acace"},{"last_affected":"d67cfbe8ddca5a50c9577ea11feaf5c94d0acace"}],"database_specific":{"extracted_events":[{"introduced":"1.4.0"},{"last_affected":"1.4.0"}],"source":"AFFECTED_FIELD"}}],"versions":["1.4.0","v1.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14541.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"}]}