Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

The vendor has implemented countermeasures to mitigate this vulnerability and is in effect as of 9/18/2026. Affected users are encouraged to contact them for more information at ( https://www.mrsteam.com/contactus/ ).


Workaround

No workaround given by the vendor.

History

Thu, 24 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.
Title MrSteam iSteamX Improper Isolation or Compartmentalization
Weaknesses CWE-653
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T20:39:59.975Z

Reserved: 2026-09-22T14:36:39.739Z

Link: CVE-2026-95699

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T21:18:58.613

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-95699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses