CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the mongodb_memory, elasticsearch_memory, and mem0_memory tools for storing and retrieving agent memories. We identified CVE-2026-19111, an insecure direct object reference (IDOR) issue in the mongodb_memory, elasticsearch_memory, and mem0_memory tools. Each tool uses a namespace field as the sole tenant-isolation key, and that namespace was exposed as a parameter the large language model (LLM) could control through the tool schema. A crafted prompt could cause a tool to emit a call with a forged namespace, allowing a remote authenticated user to read, modify, or delete memories belonging to other tenants, or to inject false memories into another tenant's namespace. The standalone mongodb_memory and elasticsearch_memory functions additionally exposed connection parameters, which could allow the memory layer to be redirected to an actor-specified cluster. Impacted versions: < 0.8.3 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Insecure direct object reference in memory tools allows remote authenticated users to read, modify, or delete other tenants' stored memories.
- Who is affected
- Deployments using the mongodb_memory, elasticsearch_memory, or mem0_memory tools in strands-agents-tools package.
- Urgency
- Moderate; requires authentication and depends on deployment exposure; no public exploitation reported.
- Action
- Update strands-agents-tools package and review memory tool configurations for tenant isolation controls.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Agents Tools
Get an email when a new Agents Tools advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-077-aws/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19111 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for - Insecure direct
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-71446: AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view.…nvd · 2026-08-06
- criticalCVE-2026-70558: Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter d…nvd · 2026-08-06
- criticalCVE-2026-71289: The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's defaul…nvd · 2026-08-05
- mediumCVE-2026-71286: The render-template component of ember-dynamic-render-template (addon/components/render-templa…nvd · 2026-08-05
- mediumCVE-2026-71282: ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both ge…nvd · 2026-08-05
- highCVE-2026-71276: Magistrala (formerly Mainflux)'s message-readers API reads a `format` value from the HTTP quer…nvd · 2026-08-05
More from AWS Security Bulletins
- unknownCVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Se…2026-08-05
- unknownCVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server2026-08-05
- unknownCVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project D…2026-08-04
- unknownCVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation2026-08-04
- unknownCVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools2026-08-03