Unauthorized Data Access Vulnerability in AI Agent Automation by vmDeshpande
CVE-2026-54519

8.8HIGH

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-54519?

AI Agent Automation allows for modular AI agent workflow automation. Prior to version 0.9.1, the platform’s memory handling APIs did not properly validate requests. Specifically, functions that manage memory data used identifiers provided by the request without confirming that the requester was allowed to access those identifiers. As a result, an authenticated attacker who gains access to another user's agentId or memory _id can view sensitive memory content, including conversation history and task data, as well as manipulate memory records. This vulnerability compromises data isolation between users, potentially leading to unauthorized data exposure and loss. The issue was rectified in version 0.9.1.

Affected Version(s)

ai-agent-automation < 0.9.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.