CVE-2026-92943

Published: Set 17, 2026 Last Modified: Set 17, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,2
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 8,1
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated hostname by a certificate authority present in the device trust store.

To remediate this issue, users should upgrade to version 1.6.1.

297

Improper Validation of Certificate with Host Mismatch

Incomplete
Common Consequences
Security Scopes Affected:
Access Control Authentication Other
Potential Impacts:
Gain Privileges Or Assume Identity Other
Applicable Platforms
Technologies: Not Technology-Specific, Mobile, Web Based
View CWE Details
https://aws.amazon.com/security/security-bulletins/2026-114-aws/
https://github.com/aws/aws-iot-device-sdk-python/releases/tag/v1.6.1
https://github.com/aws/aws-iot-device-sdk-python/security/advisories/GHSA-g7vp-…
https://pypi.org/project/AWSIoTPythonSDK/1.6.1/