Junglewise Threat Intelligence

CVE-2026-10557: Yarbo Mobile App and Cloud hard-coded MQTT credentials

CVE-2026-10557 · Severity: critical · CVSS 9.8 · Published 2026-06-12

Vendors: Yarbo.

Executive brief

Yarbo produces autonomous yard robots, such as snowblowers and lawn mowers, managed via mobile apps. A security flaw was found where the mobile applications used the same hard-coded login credentials for every user and robot worldwide. An attacker could use these credentials to track the real-time location of any Yarbo robot and potentially send unauthorized movement or operational commands, posing a physical safety risk and a significant privacy breach.

Technical details

The Yarbo mobile applications (Android and iOS) utilize hard-coded MQTT broker credentials (CWE-798) that are shared across the entire product ecosystem. These credentials can be easily extracted by decompiling the application binary (APK/IPA). Once obtained, an attacker can connect to the Yarbo cloud MQTT infrastructure without further authentication. The vulnerability allows for wildcard subscriptions to telemetry topics, exposing real-time data for all robots globally. Furthermore, by using a robot's serial number (which is visible in the telemetry stream), an attacker can publish messages to a robot's command topic to remotely control its operations. A fix is available in mobile app version 3.17.4 and via server-side authorization updates deployed in May 2026.

Affected products

  • Yarbo Yarbo Android mobile application < v3.17.4
  • Yarbo Yarbo iOS mobile application < v3.17.4
  • Yarbo Cloud MQTT infrastructure All versions prior to May 2026 update

Timeline

  • 2026-06-11: advisory: Initial publication of ICSA-26-162-01 by CISA
  • 2026-06-12: disclosed: CVE-2026-10557 published to NVD
  • 2026-05-01: patched: Server-side broker authorization enforcement and mobile app update 3.17.4 released

References

Related threats