Description
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying through the related Agent that the record belongs to req.user. An authenticated attacker who knows or obtains another user's identifiers can read victim AgentMemory content, including conversation history, agent context, task data, embeddings, and metadata, delete an individual victim memory, or clear all memory belonging to a victim agent. This breaks tenant isolation and causes unauthorized disclosure and data loss. This issue is fixed in version 0.9.1.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure and Loss
Action: Patch
AI Analysis

Impact

AI Agent Automation contains missing ownership checks in its memory APIs for versions prior to 0.9.1. The memory controller authenticates requests but fails to verify that the caller’s agent or memory identifiers belong to the authenticated user. An attacker who is authenticated and knows or obtains another user’s agentId or memory _id can read confidential memory content, delete a single memory entry, or clear all memory of that victim agent. This results in unauthorized disclosure of conversation history, agent context, task data, embeddings, and metadata, and causes data loss. The flaw aligns with CWE‑862 – Restricted Write Access.

Affected Systems

The vulnerability affects the modular AI agent workflow automation platform developed by vmDeshpande, specifically the AI Agent Automation product. All releases earlier than 0.9.1 are impacted; version 0.9.1 and later contain the fix.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% reflects a low probability of exploitation at this time. The issue is not yet listed in the CISA KEV catalog. The likely attack vector is an authenticated user who has or can obtain another user’s identifiers; no local or remote code execution is required. Once exploited, the attacker can read or delete sensitive data across tenant boundaries, leading to significant confidentiality and integrity violations. No public exploits are known, but the high impact warrants prompt remediation.

Generated by OpenCVE AI on September 19, 2026 at 01:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AI Agent Automation to version 0.9.1 or later to apply the ownership check fix.
  • If upgrading immediately is not possible, restrict or disable listMemories, deleteMemory, and clearAgentMemory endpoints for users who are not the owners of the target agent, enforcing an ownership validation guard in the code.
  • Perform a thorough code review of all API endpoints that handle user data to ensure similar ownership or access controls are in place, and apply patches for any identified gaps.

Generated by OpenCVE AI on September 19, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Vmdeshpande
Vmdeshpande ai-agent-automation
Vendors & Products Vmdeshpande
Vmdeshpande ai-agent-automation

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying through the related Agent that the record belongs to req.user. An authenticated attacker who knows or obtains another user's identifiers can read victim AgentMemory content, including conversation history, agent context, task data, embeddings, and metadata, delete an individual victim memory, or clear all memory belonging to a victim agent. This breaks tenant isolation and causes unauthorized disclosure and data loss. This issue is fixed in version 0.9.1.
Title AI Agent Automation: Missing ownership checks in memory APIs allow cross-user memory read and deletion
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Vmdeshpande Ai-agent-automation
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T01:56:49.730Z

Reserved: 2026-06-15T18:40:01.650Z

Link: CVE-2026-54519

cve-icon Vulnrichment

Updated: 2026-09-22T01:56:45.479Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:00.930

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses