CVE-2026-95699

CRITICAL Status: Deferred

CVSS Scores

CVSS v3.x Base Score
9.6
CRITICAL

Description

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.

Published
September 24, 2026 9:18 PM
Last Modified
September 24, 2026 9:25 PM
Source
[email protected]

Weaknesses (CWE)

CWE-653

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.