Credential disclosure in Strands Agents Tools elasticsearch_memory tool
UnratedCVE-2026-15746 · Published Jul 15, 2026 · updated Sep 22, 2026
Bulletin ID: 2026-056-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 11:30 AM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746 , a server-side request forgery (SSRF) issue in the elasticsearch_memory tool. The tool exposed its connection parameters (es_url, cloud_id, api_key) as fields the large language model (LLM) could control through the tool schema. When a caller omitted the api_key parameter, the tool fell back to the operator's ELASTICSEARCH_API_KEY environment variable and sent it to whichever host the LLM specified. A crafted prompt could cause the tool to connect to a threat-actor-controlled server and disclose the operator's Elasticsearch API key in the Authorization header. Impacted versions: Resolution: This issue has been addressed in strands-agents-tools version 0.7.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. As ...
Affected versions
Details and references
Bulletin ID: 2026-056-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 11:30 AM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746 , a server-side request forgery (SSRF) issue in the elasticsearch_memory tool. The tool exposed its connection parameters (es_url, cloud_id, api_key) as fields the large language model (LLM) could control through the tool schema. When a caller omitted the api_key parameter, the tool fell back to the operator's ELASTICSEARCH_API_KEY environment variable and sent it to whichever host the LLM specified. A crafted prompt could cause the tool to connect to a threat-actor-controlled server and disclose the operator's Elasticsearch API key in the Authorization header. Impacted versions: Resolution: This issue has been addressed in strands-agents-tools version 0.7.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. As a precautionary measure, we recommend all operators rotate their ELASTICSEARCH_API_KEY, even if there is no indication the credential was exposed. Workarounds: Avoid using the elasticsearch_memory tool until you upgrade to version 0.7.0 or later. If you must continue running an affected version, do not expose the ELASTICSEARCH_API_KEY environment variable to the tool, and restrict outbound network access so the agent host can reach only your trusted Elasticsearch endpoint. References: CVE-2026-15746 GHSA-ppcf-fpr3-x46v Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-056-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-15746 - Credential disclosure in Strands Agents Tools elasticsearch_memory tool Bulletin ID: 2026-056-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 11:30 AM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746 , a server-side request forgery (SSRF) issue in the elasticsearch_memory tool. The tool exposed its connection parameters (es_url, cloud_id, api_key) as fields the large language model (LLM) could control through the tool schema. When a caller omitted the api_key parameter, the tool fell back to the operator's ELASTICSEARCH_API_KEY environment variable and sent it to whichever host the LLM specified. A crafted prompt could cause the tool to connect to a threat-actor-controlled server and disclose the operator's Elasticsearch API key in the Authorization header. Impacted versions: Resolution: This issue has been addressed in strands-agents-tools version 0.7.0 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. As a precautionary
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | Path traversal and arbitrary file write in the workflow linters of... | Unrated | No fix yet |
| Jul 17 | Issue with Athena Federated Query Synapse Connector | Unrated | No fix yet |
| Jul 16 | Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK | Unrated | No fix yet |
| Jul 15 | OS command injection in jsii-diff in AWS jsii | Unrated | No fix yet |
| Jul 14 | aws-load-balancer-controller: insufficient isolation | Medium5.8 | 3.4.2 |
| Jul 14 | AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL | Unrated | No fix yet |