Junglewise Threat Intelligence

CVE-2026-54519: AI Agent Automation memory authorization bypass

CVE-2026-54519 · Severity: high · CVSS 8.8 · Published 2026-09-17

Executive brief

AI Agent Automation is a platform for building and managing AI agent workflows. An authentication flaw allows authenticated users to read, delete, or clear memory belonging to other users' agents by guessing or obtaining their identifiers, exposing sensitive conversation history, task data, and agent context while breaking the isolation between tenants.

Technical details

The vulnerability is a missing authorization check (CWE-639) in the memory.controller.js backend endpoints. The listMemories, deleteMemory, and clearAgentMemory functions accept caller-supplied agentId or memory _id parameters without verifying that the resource belongs to the authenticated user (req.user). An authenticated attacker can enumerate or guess other users' agent IDs to access or delete their AgentMemory documents, including conversation history, embeddings, and metadata. The attack requires network access to the API and an authenticated session, but no special privileges. The fix (v0.9.1) adds ownership validation by verifying each agent belongs to the authenticated user before granting access to its memory.

Affected products

  • vmDeshpande AI Agent Automation prior to 0.9.1

Timeline

  • 2026-09-17: disclosed: CVE-2026-54519 published on NVD
  • 2026-06-04: patched: Fix committed to main branch
  • 2026-06-05: other: Version 0.9.1 released with security fixes

References

Related threats