CVE Tools
Back to feed
Advisory Yarbo Android app mobile Yarbo iOS app Yarbo auth-bypass

Critical Yarbo Robot Vulnerability Exposes Global Fleet

Daily CyberSecurity (securityonline.info)·By Do Son··2 min read
CVE Tools coverage

Researchers report that Yarbo Android and iOS apps contain hard-coded MQTT credentials, tracked as CVE-2026-10557, which can be extracted from the apps and used to access MQTT brokers supporting a large global robot fleet. A second issue, CVE-2026-7368, is a lack of proper per-device/per-user authorization in the Yarbo cloud, meaning a single valid login could allow fleet-wide access. This matters because attackers may be able to subscribe to telemetry and issue commands across many robots rather than affecting only one device.