A vulnerability categorized as problematic has been discovered in Google mcp-toolbox up to 1.4.0. This affects an unknown part of the component BigQuery Execute-Sql Tool. Such manipulation leads to improper authorization.
This vulnerability is referenced as CVE-2026-14538. It is possible to launch the attack remotely. No exploit is available.