Description
Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter.



To remediate this issue, users should upgrade to version 0.8.3.
Published: 2026-08-06
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an insecure direct object reference that allows a remote authenticated user to manipulate the namespace field sent to the memory tools (mongodb_memory, elasticsearch_memory, mem0_memory) in Amazon Strands Agents Tools. By forcing the tool to emit calls with a forged namespace, the attacker can read, modify, or delete memories stored for other tenants. This results in a confidentiality breach and denial of data integrity for the affected tenants.

Affected Systems

AWS Strands Agents Tools prior to version 0.8.3; any deployment that uses the memory tools without the 0.8.3 patch is vulnerable.

Risk and Exploitability

The CVSS score of 8.6 reflects a high severity scenario where an authenticated user can impact data of other tenants. The EPSS score is not available, but the KEV catalog does not list the vulnerability, suggesting no widespread exploitation has been observed yet. Exploitation requires the attacker to be authenticated to use the tools and to influence the LLM to generate a tool call with a forged namespace; assuming access to that capability, the attack path is straightforward and does not require database credentials.

Generated by OpenCVE AI on August 7, 2026 at 00:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AWS Strands Agents Tools to version 0.8.3 or later to remove the vulnerability.
  • If immediate upgrade is not possible, enforce strict validation of the namespace parameter so that only authorized tenants can specify the namespace used by the memory tools.
  • Monitor tool call logs for unexpected namespace values and investigate any unauthorized access attempts promptly.

Generated by OpenCVE AI on August 7, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter. To remediate this issue, users should upgrade to version 0.8.3.
Title Insecure direct object reference in Strands Agents Tools memory tool namespace isolation
First Time appeared Aws
Aws strands-agents-tools
Weaknesses CWE-639
CPEs cpe:2.3:a:aws:strands-agents-tools:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws strands-agents-tools
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Aws Strands-agents-tools
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-08-06T18:05:05.139Z

Reserved: 2026-08-06T14:01:29.573Z

Link: CVE-2026-19111

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:30:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key