CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-14538

unknowncovered by 1 sourcefirst seen 2026-07-31
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a fail-open logic flaw, it bypasses validation when the API returns an empty array for specialized constructs. This allows the attacker to extract structural DDL schemas for explicitly excluded datasets via INFORMATION_SCHEMA, and access downstream federated row data via EXTERNAL_QUERY connections.

⚡ Watch CVE-2026-14538

Get an email if CVE-2026-14538 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-14538

CVE.org record

Embed the live status

CVE-2026-14538 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-14538 status](https://www.csirts.com/badge/CVE-2026-14538)](https://www.csirts.com/cve/CVE-2026-14538)