CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the mongodb_memory, elasticsearch_memory, and mem0_memory tools for storing and retrieving agent memories. We identified CVE-2026-19111, an insecure direct object reference (IDOR) issue in the mongodb_memory, elasticsearch_memory, and mem0_memory tools. Each tool uses a namespace field as the sole tenant-isolation key, and that namespace was exposed as a parameter the large language model (LLM) could control through the tool schema. A crafted prompt could cause a tool to emit a call with a forged namespace, allowing a remote authenticated user to read, modify, or delete memories belonging to other tenants, or to inject false memories into another tenant's namespace. The standalone mongodb_memory and elasticsearch_memory functions additionally exposed connection parameters, which could allow the memory layer to be redirected to an actor-specified cluster. Impacted versions: < 0.8.3 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AI Analysis
Technical Summary
Strands Agents is an open-source SDK for AI agents, with strands-agents-tools providing memory storage tools such as mongodb_memory, elasticsearch_memory, and mem0_memory. CVE-2026-19111 is an IDOR vulnerability where the namespace parameter, used for tenant isolation, is exposed to manipulation by the large language model controlling the tool schema. This flaw enables a remote authenticated user to forge namespaces, thereby reading, modifying, deleting, or injecting memories across tenant boundaries. Moreover, the standalone mongodb_memory and elasticsearch_memory tools expose connection parameters, potentially allowing redirection of memory operations to attacker-specified clusters. The vulnerability affects all versions before 0.8.3. The vendor has released version 0.8.3 to address this issue and recommends upgrading. Workarounds include avoiding deployment of these tools in multi-tenant environments or restricting to single-tenant setups with fixed namespaces and avoiding standalone functions that accept connection parameters.
Potential Impact
A remote authenticated user can exploit this vulnerability to bypass tenant isolation by forging namespaces, leading to unauthorized reading, modification, deletion, or injection of memories belonging to other tenants. This compromises data confidentiality and integrity within multi-tenant AI agent deployments. Additionally, exposure of connection parameters in standalone tools could allow attackers to redirect memory operations to clusters under their control, potentially enabling further unauthorized access or data manipulation.
Mitigation Recommendations
An official fix is available in strands-agents-tools version 0.8.3. It is strongly recommended to upgrade to this version to remediate the vulnerability. Until upgrading, do not deploy the mongodb_memory, elasticsearch_memory, or mem0_memory tools in multi-tenant agent environments where multiple tenants share a single deployment. Restrict these tools to single-tenant deployments with a fixed namespace per request. Avoid using the standalone mongodb_memory or elasticsearch_memory functions that accept connection parameters to prevent redirection attacks.
CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
Description
Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the mongodb_memory, elasticsearch_memory, and mem0_memory tools for storing and retrieving agent memories. We identified CVE-2026-19111, an insecure direct object reference (IDOR) issue in the mongodb_memory, elasticsearch_memory, and mem0_memory tools. Each tool uses a namespace field as the sole tenant-isolation key, and that namespace was exposed as a parameter the large language model (LLM) could control through the tool schema. A crafted prompt could cause a tool to emit a call with a forged namespace, allowing a remote authenticated user to read, modify, or delete memories belonging to other tenants, or to inject false memories into another tenant's namespace. The standalone mongodb_memory and elasticsearch_memory functions additionally exposed connection parameters, which could allow the memory layer to be redirected to an actor-specified cluster. Impacted versions: < 0.8.3 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Strands Agents is an open-source SDK for AI agents, with strands-agents-tools providing memory storage tools such as mongodb_memory, elasticsearch_memory, and mem0_memory. CVE-2026-19111 is an IDOR vulnerability where the namespace parameter, used for tenant isolation, is exposed to manipulation by the large language model controlling the tool schema. This flaw enables a remote authenticated user to forge namespaces, thereby reading, modifying, deleting, or injecting memories across tenant boundaries. Moreover, the standalone mongodb_memory and elasticsearch_memory tools expose connection parameters, potentially allowing redirection of memory operations to attacker-specified clusters. The vulnerability affects all versions before 0.8.3. The vendor has released version 0.8.3 to address this issue and recommends upgrading. Workarounds include avoiding deployment of these tools in multi-tenant environments or restricting to single-tenant setups with fixed namespaces and avoiding standalone functions that accept connection parameters.
Potential Impact
A remote authenticated user can exploit this vulnerability to bypass tenant isolation by forging namespaces, leading to unauthorized reading, modification, deletion, or injection of memories belonging to other tenants. This compromises data confidentiality and integrity within multi-tenant AI agent deployments. Additionally, exposure of connection parameters in standalone tools could allow attackers to redirect memory operations to clusters under their control, potentially enabling further unauthorized access or data manipulation.
Mitigation Recommendations
An official fix is available in strands-agents-tools version 0.8.3. It is strongly recommended to upgrade to this version to remediate the vulnerability. Until upgrading, do not deploy the mongodb_memory, elasticsearch_memory, or mem0_memory tools in multi-tenant agent environments where multiple tenants share a single deployment. Restrict these tools to single-tenant deployments with a fixed namespace per request. Avoid using the standalone mongodb_memory or elasticsearch_memory functions that accept connection parameters to prevent redirection attacks.
Technical Details
- Classification
- {"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-077-aws/","fetched":true,"fetchedAt":"2026-08-06T18:26:55.862Z","wordCount":277}
Threat ID: 6a74d1efbf8831d539259396
Added to database: 08/06/2026, 18:26:55 UTC
Last enriched: 08/13/2026, 20:55:58 UTC
Last updated: 09/18/2026, 22:01:32 UTC
Views: 94
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.