CVE-2026-16481

Google · MCP Toolbox for Databases

A Server-Side Request Forgery vulnerability in the cloud-healthcare-fhir-fetch-page tool of the Google MCP Toolbox allows for credential exfiltration and unauthorized internal requests.

Executive summary

The Google MCP Toolbox for Databases is susceptible to a Server-Side Request Forgery vulnerability that enables attackers to exfiltrate credentials and perform unauthorized internal requests.

Vulnerability

This is a Server-Side Request Forgery (CWE-918) vulnerability located within the cloud-healthcare-fhir-fetch-page utility. An authenticated user with low privileges can manipulate the tool to send requests to arbitrary internal endpoints, potentially resulting in the exfiltration of sensitive service credentials.

Business impact

The potential for credential exfiltration poses a significant risk to cloud infrastructure security, as stolen credentials could be used to escalate privileges or access other protected services within the environment. While the vulnerability requires authenticated access, the high CVSS score of 8.4 reflects the substantial impact on internal network and service security.

Remediation

Immediate Action: Apply the vendor-provided security updates for the MCP Toolbox for Databases as soon as they become available.

Proactive Monitoring: Review audit logs for unusual egress traffic or requests originating from the MCP Toolbox service that target internal metadata services or unauthorized network segments.

Compensating Controls: Restrict the service's network access via security groups or firewalls to ensure it can only communicate with required external and internal resources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the Google MCP Toolbox should prioritize identifying and updating the affected component. Given the risk of credential theft, administrators should also rotate any credentials that may have been accessible to the service during the period of vulnerability.