Improper Certificate Validation in AWS IoT Device SDK for Python
CVE-2026-92943

9.2CRITICAL

Key Information:

Vendor

Aws

Vendor
CVE Published:
17 September 2026

What is CVE-2026-92943?

There is an improper validation of certificates with host mismatch in the MQTT client TLS connection layer of the AWS IoT Device SDK for Python. This vulnerability affects versions 1.5.3 through 1.6.0 on Python 3.7 and later, allowing an attacker to potentially impersonate AWS IoT Core endpoints. An adversary-in-the-middle may exploit this vulnerability to read device telemetry and inject arbitrary MQTT messages that the affected device may interpret as legitimate. Users are advised to upgrade to version 1.6.1 to mitigate this risk.

Affected Version(s)

AWSIoTPythonSDK 1.5.3 <= 1.6.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.