CVE-2026-92943
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated hostname by a certificate authority present in the device trust store. To remediate this issue, users should upgrade to version 1.6.1.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- CWE
- CWE-297
- Published
- 2026-09-17
- Last modified
- 2026-09-17
Affected products
- AWS AWSIoTPythonSDK
Weakness type
Related vulnerabilities
- CVE-2020-11050 — Improper Validation of Certificate with Host Mismatch in Java-WebSocket
- CVE-2021-21385 — Disabled hostname verification and accepting self-signed certificates
- CVE-2025-3501 — Org.keycloak.protocol.services: keycloak hostname verification
- CVE-2018-10936 — A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t
- CVE-2022-32153 — Splunk Enterprise lacked TLS host name validation
- CVE-2026-59638 — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2026-15925 — Improper TLS Hostname Verification in Snowflake Connector for Python