CVE-2026-11718
Google MCP Toolbox for Databases (googleapis/mcp-toolbox)
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, the subsequent claim-checking logic (validateClaims) evaluates the issuer condition as if a.issuer != "" && iss != "". If the external OAuth provider's introspection response omits the optional iss (issuer) field completely, the variable iss defaults to an empty string. This causes the conditional...
- CVSS
- 9.3
- EPSS
- 0.20% 10.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18