CVE-2026-95699 Details
Description
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.
A vulnerability in the iSteamX mobile application prior to September 18, 2026, allowed authenticated users to access wildcard MQTT topics through the application's AWS policy. This access could expose other users' device data and enable the attacker to remotely start or stop connected devices, potentially leading to unauthorized activation of steam generators and exposure of user profile information.
The vendor has implemented countermeasures to mitigate this vulnerability, effective as of September 18, 2026. Affected users are encouraged to contact MrSteam for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-653 | Improper Isolation or Compartmentalization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MrSteam iSteamX | v1.3.42_(build_44) |
CPE
Remediation
| |
| MrSteam iSteamX Hub | v4.2.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion