CVE-2026-19111: Insecure direct object reference in Strands Agents Tools memory tool namespace isolation
Insecure direct object reference in the mongodbmemory, elasticsearchmemory, and mem0memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter.
To remediate this issue, users should upgrade to version 0.8.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Strands Agents Toolsto a version that resolves this vulnerability.Fixed in 0.8.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19111?
The severity of CVE-2026-19111 is rated high with a score of 8.1.
How do I fix CVE-2026-19111?
To fix CVE-2026-19111, update the Amazon Strands Agents Tools to version 0.8.3 or later.
What are the affected tools in CVE-2026-19111?
The affected tools in CVE-2026-19111 include mongodb_memory, elasticsearch_memory, and mem0_memory.
What impact does CVE-2026-19111 have?
CVE-2026-19111 may allow remote authenticated users to access, modify, or delete memories belonging to other tenants.
When was CVE-2026-19111 published?
CVE-2026-19111 was published on August 6, 2026.