Critical Yarbo Robot Vulnerability Exposes Global Fleet
AdvisoryYarbo Android appYarbo iOS appOur summary
Researchers report that Yarbo Android and iOS apps contain hard-coded MQTT credentials, tracked as CVE-2026-10557, which can be extracted from the apps and used to access MQTT brokers supporting a large global robot fleet. A second issue, CVE-2026-7368, is a lack of proper per-device/per-user authorization in the Yarbo cloud, meaning a single valid login could allow fleet-wide access. This matters because attackers may be able to subscribe to telemetry and issue commands across many robots rather than affecting only one device.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.