Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authorization
CVE-2026-7368
8.6HIGH
What is CVE-2026-7368?
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). Even after removal of hard-coded credentials from the app, a single compromised credential could still provide fleet-wide access without per-device access controls.
Affected Version(s)
Yarbo Android/IOS mobile application 0 < 3.17.4
Yarbo Cloud MQTT infrastructure All
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Markus Lassfolk of Truesec reported this vulnerability to CISA.
