CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
CVE-2026-19111 is an insecure direct object reference (IDOR) vulnerability in the strands-agents-tools package, specifically affecting the mongodb_memory, elasticsearch_memory, and mem0_memory tools used for storing and retrieving AI agent memories. The vulnerability arises because the namespace field, used as the sole tenant-isolation key, can be controlled by the large language model (LLM) through the tool schema. This allows a remote authenticated user to forge namespaces and access or manipulate memories belonging to other tenants. Additionally, the standalone mongodb_memory and elasticsearch_memory tools expose connection parameters that could be redirected to attacker-controlled clusters. The issue affects versions prior to 0.8.3 and has been fixed in version 0.8.3. Until patched, it is recommended to avoid deploying these tools in multi-tenant environments or to restrict them to single-tenant deployments with fixed namespaces.
AI Analysis
Technical Summary
Strands Agents is an open-source SDK for AI agents, with strands-agents-tools providing memory storage tools including mongodb_memory, elasticsearch_memory, and mem0_memory. CVE-2026-19111 is an IDOR vulnerability where the namespace parameter, used for tenant isolation, is exposed and controllable by the LLM via the tool schema. This flaw allows a remote authenticated user to forge namespace values, enabling unauthorized reading, modification, deletion, or injection of memories across tenants. The standalone mongodb_memory and elasticsearch_memory tools also expose connection parameters, potentially allowing redirection of memory storage to attacker-specified clusters. The vulnerability affects versions before 0.8.3 and has been addressed in strands-agents-tools version 0.8.3.
Potential Impact
A remote authenticated user can exploit this vulnerability to access, modify, delete, or inject false memories into other tenants' namespaces, violating tenant isolation and data confidentiality. The exposure of connection parameters in standalone tools further risks redirecting memory storage to malicious clusters, potentially compromising data integrity and confidentiality across tenants.
Mitigation Recommendations
This vulnerability is fixed in strands-agents-tools version 0.8.3. Users should upgrade to version 0.8.3 or later to remediate the issue. Until upgrading, do not deploy the mongodb_memory, elasticsearch_memory, or mem0_memory tools in multi-tenant agents where end users share a single agent deployment. Restrict these tools to single-tenant deployments with fixed namespaces and avoid using standalone mongodb_memory or elasticsearch_memory functions that accept connection parameters.
CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
Description
CVE-2026-19111 is an insecure direct object reference (IDOR) vulnerability in the strands-agents-tools package, specifically affecting the mongodb_memory, elasticsearch_memory, and mem0_memory tools used for storing and retrieving AI agent memories. The vulnerability arises because the namespace field, used as the sole tenant-isolation key, can be controlled by the large language model (LLM) through the tool schema. This allows a remote authenticated user to forge namespaces and access or manipulate memories belonging to other tenants. Additionally, the standalone mongodb_memory and elasticsearch_memory tools expose connection parameters that could be redirected to attacker-controlled clusters. The issue affects versions prior to 0.8.3 and has been fixed in version 0.8.3. Until patched, it is recommended to avoid deploying these tools in multi-tenant environments or to restrict them to single-tenant deployments with fixed namespaces.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Strands Agents is an open-source SDK for AI agents, with strands-agents-tools providing memory storage tools including mongodb_memory, elasticsearch_memory, and mem0_memory. CVE-2026-19111 is an IDOR vulnerability where the namespace parameter, used for tenant isolation, is exposed and controllable by the LLM via the tool schema. This flaw allows a remote authenticated user to forge namespace values, enabling unauthorized reading, modification, deletion, or injection of memories across tenants. The standalone mongodb_memory and elasticsearch_memory tools also expose connection parameters, potentially allowing redirection of memory storage to attacker-specified clusters. The vulnerability affects versions before 0.8.3 and has been addressed in strands-agents-tools version 0.8.3.
Potential Impact
A remote authenticated user can exploit this vulnerability to access, modify, delete, or inject false memories into other tenants' namespaces, violating tenant isolation and data confidentiality. The exposure of connection parameters in standalone tools further risks redirecting memory storage to malicious clusters, potentially compromising data integrity and confidentiality across tenants.
Mitigation Recommendations
This vulnerability is fixed in strands-agents-tools version 0.8.3. Users should upgrade to version 0.8.3 or later to remediate the issue. Until upgrading, do not deploy the mongodb_memory, elasticsearch_memory, or mem0_memory tools in multi-tenant agents where end users share a single agent deployment. Restrict these tools to single-tenant deployments with fixed namespaces and avoid using standalone mongodb_memory or elasticsearch_memory functions that accept connection parameters.
Technical Details
- Classification
- {"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-077-aws/","fetched":true,"fetchedAt":"2026-08-06T18:26:55.862Z","wordCount":277}
Threat ID: 6a74d1efbf8831d539259396
Added to database: 08/06/2026, 18:26:55 UTC
Last enriched: 08/06/2026, 18:27:07 UTC
Last updated: 08/06/2026, 20:19:32 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.