Insecure Direct Object Reference in Amazon Strands Agents Tools
CVE-2026-19111

8.6HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
6 August 2026

What is CVE-2026-19111?

The Amazon Strands Agents Tools contain an insecure direct object reference vulnerability that affects the mongodb_memory, elasticsearch_memory, and mem0_memory functionalities. This issue allows remote authenticated users to manipulate the LLM into making tool calls with a forged namespace parameter, potentially granting access to, or even allowing modifications and deletions of, memories that belong to other tenants. It is crucial for users to upgrade to version 0.8.3 to mitigate this risk.

Affected Version(s)

strands-agents-tools 0 < 0.8.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.