CVE-2026-7368
Last modified
CVE-2026-7368 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). Even after removal of hard-coded credentials from the app, a single compromised credential could still provide fleet-wide access without per-device access controls.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7368?
How severe is CVE-2026-7368?
How do I fix CVE-2026-7368?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7360Insufficient validation of untrusted input. in Compositing i…3.1
- CVE-2026-7361Use after free in iOS in Google Chrome prior to 147.0.7727.1…8.8
- CVE-2026-7362IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6…6.5
- CVE-2026-7363Use after free in Canvas in Google Chrome on Linux, ChromeOS…8.8
- CVE-2026-7364IBM Verify Identity Access 11.0 through 11.0.2 and IBM Secur…6.1
- CVE-2026-7365IBM Operations Analytics - Log Analysis and IBM SmartCloud …7.8
- CVE-2026-7371Multiple reflected cross-site scripting (xss) vulnerabilitie…6.1
- CVE-2026-7372A stack overflow vulnerability exists in the WebCam Server L…9
- CVE-2026-7373Rapid7 Metasploit Pro is vulnerable to a local privilege esc…8.5
- CVE-2026-7374A flaw was found in KubeVirt's virt-handler component. This …9.9
- CVE-2026-7375UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4…7.5
- CVE-2026-7376Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows de…7.5
Are you affected by CVE-2026-7368?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
