Authorization Flaw in Yarbo Cloud for Robotic Systems by Yarbo
CVE-2026-7368
What is CVE-2026-7368?
The Yarbo Cloud platform contains a significant vulnerability that allows unauthorized clients to access and manipulate robotic systems. Clients equipped with either shared hard-coded credentials or individual user credentials can subscribe to broad wildcard topics that cover all robots in the fleet. This means compromised credentials can lead to exposing sensitive command topics, enabling potential manipulation of robots using just the robot's serial number unveiled in telemetry data. The lack of per-device or user-specific access controls raises substantial security concerns, particularly as the removal of hard-coded credentials does not adequately mitigate the risk posed by even a single compromised user credential.
Affected Version(s)
Yarbo Android/IOS mobile application 0 < 3.17.4
Yarbo Cloud MQTT infrastructure All
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
