Update July 24, 2026: SharkNinja contacted Vacuum Wars following publication and stated that it has “completely addressed the identified vulnerability.” The company said it takes privacy and data security seriously and remains committed to protecting consumers’ information.
A security researcher disclosed an alleged cloud security vulnerability that the researcher said could allow someone with a certificate extracted from certain Shark robot vacuums to execute commands on other compatible Shark robots within the same Amazon Web Services region.
According to the researcher, who publishes under the handle tokay0, the primary flaw was an overly permissive AWS IoT policy associated with some Shark device certificates. If exploited, the vulnerability could potentially have allowed an attacker to control affected robots and, on compatible models, access live camera feeds, stored home maps, and Wi-Fi credentials.

What Was the Shark Robot Vacuum Vulnerability?
The researcher said some Shark device certificates had broader cloud permissions than intended, allowing them to communicate with devices other than the intended robot. This type of cloud authorization issue is similar to a previously disclosed vulnerability affecting DJI robot vacuums. We covered that incident, along with other notable robot vacuum security and privacy cases, in our guide to robot vacuum security.
While monitoring one AWS region for 24 hours, the researcher observed more than 1.5 million unique Shark device serial numbers. Approximately 44% of the devices emitted a response associated with the command feature, which the researcher interpreted as evidence that those devices supported the relevant command handler.
The researcher observed those devices communicating with the cloud service rather than individually testing or compromising them. There is currently no public evidence that attackers exploited the vulnerability against Shark customers.

Has SharkNinja Addressed the Vulnerability?
According to the disclosure, the researcher first reported the issue to SharkNinja in March 2026 and publicly disclosed it in July after concluding that it remained unresolved. At the time of the original publication, no CVE had been assigned, and SharkNinja had not published a public response.
Following publication, SharkNinja contacted Vacuum Wars and stated that it was aware of the researcher’s report and had “completely addressed the identified vulnerability.” The company said it takes privacy and data security seriously and remains committed to protecting the privacy and data security of its consumers.
SharkNinja’s Vulnerability Disclosure Policy states that the company will provide regular updates for reported vulnerabilities affecting connected products until they are resolved. The researcher’s report indicated that the issue could be corrected through changes to SharkNinja’s AWS cloud configuration and should not require a firmware update for customers.
Top 20 Robot Vacuums
Explore Vacuum Wars’ always up-to-date rankings of the best robot vacuums, based on independent, hands-on testing. We purchase every unit ourselves and have evaluated more than 150 models, giving us a deep benchmark for cleaning performance, navigation, battery life, and advanced features like obstacle avoidance and mopping.
Shark Robot Vacuum Buyers Guide 2026
We outline the key distinctions among Shark robot vacuums so you can determine which features are worth the extra cost and which ones you can pass on. Whether you’re interested in a budget-friendly option or a premium model with state-of-the-art features, we’ll walk you through the essential details to help you select a Shark robot vacuum that suits both your home and your budget. See the Guide




