CVE-2026-11719: High severity MCP Toolbox for Databases vulnerability

Published Jun 18, 2026
·
Updated

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers.

While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol versions (2025-06-18, 2025-03-26, and 2024-11-05) omit this check. An authenticated client with low-privilege tokens (e.g., read) can bypass the intended per-tool scope restrictions and execute high-privilege tools (e.g., admin) simply by specifying an older protocol version in the MCP-Protocol-Version header, or by omitting the header entirely (which causes the server to default to the vulnerable 2024-11-05 handler).

Affected Software

3 affected componentsFixes available
MCP Toolbox for Databases=2025-06-18, =2025-03-26, =2024-11-05
go/github.com/googleapis/mcp-toolbox<1.4.0
1.4.0
Google Mcp Toolbox For Databases=1.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/googleapis/mcp-toolbox to a version that resolves this vulnerability.

    Fixed in 1.4.0
  2. Upgrade

    Upgrade MCP Toolbox for Databases to a version that resolves this vulnerability.

    Fixed in 2025-11-25
  3. Compensating control

    Disallow clients from using the MCP-Protocol-Version header values 2025-06-18, 2025-03-26, or 2024-11-05, and block requests that omit the MCP-Protocol-Version header (since omission defaults to the vulnerable 2024-11-05 handler).

Event History

Jun 18, 2026
CVE Published
via MITRE·11:55 AM
Data Sourced
via MITRE·11:55 AM
DescriptionWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
RemedyAffected Software
Advisory Published
via GitHub·03:32 PM
Data Sourced
via GitHub·03:32 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-11719?

The severity of CVE-2026-11719 is rated at 71 on the risk scale.

2

How do I fix CVE-2026-11719?

To fix CVE-2026-11719, ensure that you upgrade to the latest version of MCP Toolbox for Databases that includes proper scope enforcement.

3

What type of vulnerability is CVE-2026-11719?

CVE-2026-11719 is an authenticated authorization bypass vulnerability.

4

Which software is affected by CVE-2026-11719?

CVE-2026-11719 affects the MCP Toolbox for Databases.

5

What causes the vulnerability in CVE-2026-11719?

The vulnerability in CVE-2026-11719 is caused by missing scope enforcement across older protocol handlers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203