PT-2026-48886 · Yarbo · Yarbo Cloud

·

CVE-2026-7368

·

Published

2026-06-12

·

Updated

2026-06-13

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Yarbo cloud (affected versions not specified)
Description The cloud service fails to enforce per-device or per-user authorization. A client with valid credentials, including shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics that cover all robots globally. Additionally, an attacker can publish to any robot's command topic by using the robot's serial number, which is disclosed in the telemetry stream. This lack of per-device access controls allows a single compromised credential to provide fleet-wide access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7368

Affected Products

Yarbo Cloud