A vulnerability identified as critical has been detected in Google mcp-toolbox 1.3.0/1.4.0. This vulnerability affects unknown code of the component Direct HTTP API Tool Invocation Endpoint. Performing a manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-14537. The attack can be initiated remotely. There is not any exploit available.