CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
Imported from official source
Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the mongodb_memory, elasticsearch_memory, and mem0_memory tools for storing and retrieving agent memories. We identified CVE-2026-19111, an insecure direct object reference (IDOR) issue in the mongodb_memory, elasticsearch_memory, and mem0_memory tools. Each tool uses a namespace field as the sole tenant-iso...
This version
- Version
- 1 of 2
- Recorded
- September 15, 2026 20:57
- Change
- Initial
- Content hash
b0117860edcfa6b10a5f0b1ae1a16e48- All versions
- Revision history