PT-2026-68680 · Amazon · Strands-Agents-Tools

CVE-2026-19111

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Amazon Strands Agents Tools versions prior to 0.8.3
Description An insecure direct object reference exists in the mongodb memory, elasticsearch memory, and mem0 memory tools. Remote authenticated users can access, modify, or delete memories belonging to other tenants by influencing the Large Language Model (LLM) to generate tool calls using a forged namespace parameter.
Recommendations Upgrade to version 0.8.3.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19111
GHSA-MPXQ-953J-42M4

Affected Products

Strands-Agents-Tools