CVE-2026-7368
Last modified
CVE-2026-7368 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). Even after removal of hard-coded credentials from the app, a single compromised credential could still provide fleet-wide access without per-device access controls.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7368?
How severe is CVE-2026-7368?
How do I fix CVE-2026-7368?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73669The Signify Philips Hue Bridge Pro firmware embeds a Mosquit…7.3
- CVE-2026-73670A CMS contains a SQL injection vulnerability in admin/db_dat…7.2
- CVE-2026-73671Saurus CMS Community Edition contains an unauthenticated ope…6.1
- CVE-2026-73673Netis NC63 router firmware V3.0.0.3327 contains an unauthent…8.8
- CVE-2026-73678MindsDB Minds Platform version 26.1.0 and earlier contains a…10
- CVE-2026-73679ImpressCMS contains an authenticated remote code execution v…7.2
- CVE-2026-73680Cockpit CMS 2.14.0 and prior contains a command injection vu…8.8
- CVE-2026-73682Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-73683Laravel Socialite's Facebook provider contains an authentica…8.1
- CVE-2026-73692Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-73693FileRun before 2026.3.0 contains an OS command injection vul…8.8
- CVE-2026-73694FileRun before 2026.3.0 contains an OS command injection vul…7.2
Are you affected by CVE-2026-7368?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
