CVE 8.6 HIGH

Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authorization_CVE-2026-7368

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). Even after removal of hard-coded credentials from the app, a single compromised credential could still provide fleet-wide access without per-device access controls.

AI Analysis

Missing authorization vulnerability in Yarbo Android/iOS mobile application and cloud infrastructure, allowing unauthorized access to robot command topics.

Basic Information

ID CVE-2026-7368
Source icscert
Published Jun 12, 2026 at 14:01
Modified Jun 12, 2026 at 15:33

Affected Product

Vendor Yarbo
Product Yarbo Android/IOS mobile application
Affected Versions Yarbo Yarbo Android/IOS mobile application 0
Yarbo Yarbo Cloud MQTT infrastructure All

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor Yarbo
Product Yarbo Android/IOS mobile application and Cloud Infrastructure
Version 0, All

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.