CVE-2026-19111
Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the mongodb_memory, elasticsearch_memory, and mem0_memory tools for storing and retrieving agent memories. We identified CVE-2026-19111, an insecure direct object reference (IDOR) issue in the mongodb_memory, elasticsearch_memory, and mem0_memory tools. Each tool uses a namespace field as the sole tenant-isolation key, and that namespace was exposed as a parameter the large language model (LLM) could control through the tool schema. A crafted prompt could cause a tool to emit a call with a forged namespace, allowing a remote authenticated user to read, modify, or delete memories belonging to other tenants, or to inject false memories into another tenant's namespace. The standalone mongodb_memory and elasticsearch_memory functions additionally exposed connection parameters, which could allow the memory layer to be redirected to an actor-specified cluster. Impacted versions: < 0.8.3 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Insecure direct object reference in memory tools allows remote authenticated users to read, modify, or delete other tenants' stored memories.
- Who is affected
- Deployments using the mongodb_memory, elasticsearch_memory, or mem0_memory tools in strands-agents-tools package.
- Urgency
- Moderate; requires authentication and depends on deployment exposure; no public exploitation reported.
- Action
- Update strands-agents-tools package and review memory tool configurations for tenant isolation controls.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-19111
Get an email if CVE-2026-19111 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-19111)