CVE-2026-95699

9.6

MrSteam · iSteamX application

A flaw in the iSteamX AWS policy allows authenticated users to access wildcard MQTT topics, potentially exposing user data and enabling unauthorized control of connected steam devices.

Executive summary

A critical vulnerability in the MrSteam iSteamX application allows authenticated attackers to remotely manipulate steam devices and access sensitive user data.

Vulnerability

The application suffers from improper isolation of MQTT topics (CWE-653), where an authenticated user can subscribe to wildcard topics. This allows unauthorized access to data streams and control commands intended for other users, leading to physical device interference.

Business impact

The potential for unauthorized activation of steam hardware poses a significant risk of physical harm, such as scalding, to end users. With a CVSS score of 9.6, this vulnerability represents a severe threat to user safety and brand reputation, as it allows for the remote hijacking of home automation equipment.

Remediation

Immediate Action: Contact MrSteam directly via their support portal to verify if your specific deployment has received the necessary server-side countermeasures implemented on September 18, 2026.

Proactive Monitoring: Monitor account access logs and MQTT traffic for unusual subscription patterns or unexpected device activity initiated from unauthorized sources.

Compensating Controls: While specific WAF rules are difficult to apply to proprietary MQTT traffic, restricting network access to the iSteamX Hub to known, trusted IP ranges can limit the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this vulnerability and the potential for physical harm, administrators must verify the status of their infrastructure with the vendor immediately. Ensure all firmware and application versions are updated to the latest available releases to maintain the integrity of the device control environment.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Darren Challis, per the CVE Program record.