CVE-2026-95699
Last modified
CVE-2026-95699 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MrSteam | iSteamX application | v1.3.42 (build 44) |
| MrSteam | iSteamX Hub | v4.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-95699?
How severe is CVE-2026-95699?
How do I fix CVE-2026-95699?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-95682MISP contains a stored cross-site scripting (XSS) vulnerabil…4.8
- CVE-2026-95683In MISP, the Overmind event view enriches an event with its …5.3
- CVE-2026-95685MISP contains an access control flaw in the EventReports fun…5.3
- CVE-2026-95693In MISP, the EventReport::uploadPicture method in processed …5.3
- CVE-2026-95697MISP contains an authorization flaw in the Organisation mode…5.3
- CVE-2026-95698The findOrgImage method in MISP's OrgImgHelper constructs a …5.3
- CVE-2026-9570The Taskbuilder WordPress plugin before 5.0.8 does not prop…7.1
- CVE-2026-95701In MISP, the __statisticsOrgs method in UsersController.php …5.1
- CVE-2026-95703In MISP, the OrganisationsController::__uploadLogo method pr…5.1
- CVE-2026-9571Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.1…6.5
- CVE-2026-9572A security vulnerability has been detected in GPAC up to 2.4…5.5
- CVE-2026-9573A vulnerability was detected in itsourcecode Student Transcr…7.3
Are you affected by CVE-2026-95699?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
