CVE-2026-95699
Deferred Deferred - Pending Action

AWS Policy Misconfiguration Exposes iSteamX MQTT Topics

Vulnerability report for CVE-2026-95699, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: ICS-CERT

Description

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The iSteamX mobile app had an AWS policy flaw before 9/18/2026 that allowed authenticated users to access wildcard MQTT topics. This exposed other users' device data and let attackers control connected devices, risking user profile leaks and unintended device activation like scalding.

Impact Analysis

This vulnerability could expose your device data, profile information, and allow attackers to start or stop your connected devices without consent. This may lead to privacy breaches or physical harm, such as unintended device activation causing scalding.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized data exposure and HIPAA if user health-related device data is compromised. It risks non-compliance with privacy and security requirements, potentially leading to legal penalties and reputational damage.

Mitigation Strategies

Update the iSteamX mobile application to the latest version released after 9/18/2026 to ensure the AWS policy no longer grants wildcard MQTT topic access. Review and restrict AWS IAM policies to prevent unauthorized access to MQTT topics and user data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95699. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart