Junglewise Threat Intelligence

CVE-2026-15746: Amazon Strands Agents Tools SSRF in elasticsearch_memory tool

CVE-2026-15746 · Severity: high · CVSS 6.5 · Published 2026-07-15

Technologies: Amazon Strands-Agents-Tools, Amazon AWS. Vendors: Amazon Web Services, Amazon, AWS.

Executive brief

Strands Agents Tools includes a component that interacts with Elasticsearch databases for agent memory management. A flaw in the elasticsearch_memory tool can inadvertently expose database credentials to unauthorized parties, potentially allowing attackers to access sensitive data stored in Elasticsearch clusters. This could result in data theft, unauthorized modifications, or service disruption for organizations relying on this agent toolkit.

Technical details

CVE-2026-15746 is a credential disclosure vulnerability in the elasticsearch_memory tool provided by Strands Agents Tools. The vulnerability allows sensitive Elasticsearch authentication credentials to be improperly exposed, potentially through log files, error messages, memory dumps, or insecure credential handling within the tool. This is a client-side vulnerability affecting the tool's credential management. An attacker with access to exposed credentials can authenticate directly to Elasticsearch clusters, bypassing application-level access controls. The vulnerability requires no special network positioning or user interaction beyond deploying the affected tool. As of the publication date, AWS has issued a security bulletin recommending users review their credential exposure and rotate affected Elasticsearch credentials.

Affected products

  • AWS Strands Agents Tools <UNKNOWN>

Timeline

  • 2026-09-22: disclosed

References

Related threats