THREAT OPS › Threat News › [NVD] CVE-2026-14538 (HIGH 7.7) — An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry
[NVD] CVE-2026-14538 (HIGH 7.7) — An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry
CVE-2026-14538 CVSS: 7.7 HIGH Published: 2026-07-31T02:16:28.757
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a
Indicators of compromise
- CVE-2026-14538cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14538