Authorization Flaw in Yarbo Cloud for Robotic Systems by Yarbo
CVE-2026-7368

8.6HIGH

What is CVE-2026-7368?

The Yarbo Cloud platform contains a significant vulnerability that allows unauthorized clients to access and manipulate robotic systems. Clients equipped with either shared hard-coded credentials or individual user credentials can subscribe to broad wildcard topics that cover all robots in the fleet. This means compromised credentials can lead to exposing sensitive command topics, enabling potential manipulation of robots using just the robot's serial number unveiled in telemetry data. The lack of per-device or user-specific access controls raises substantial security concerns, particularly as the removal of hard-coded credentials does not adequately mitigate the risk posed by even a single compromised user credential.

Affected Version(s)

Yarbo Android/IOS mobile application 0 < 3.17.4

Yarbo Cloud MQTT infrastructure All

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Markus Lassfolk of Truesec reported this vulnerability to CISA.
.