Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools

Amazon Web Services Version 1 original

Imported from official source

Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the mongodb_memory, elasticsearch_memory, and mem0_memory tools for storing and retrieving agent memories. We identified CVE-2026-19111, an insecure direct object reference (IDOR) issue in the mongodb_memory, elasticsearch_memory, and mem0_memory tools. Each tool uses a namespace field as the sole tenant-iso...

This version

Version
1 of 2
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
b0117860edcfa6b10a5f0b1ae1a16e48
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.