Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass

[MALFUNCTION]

May 11, 2026 · Yarbo · Yarbo Lawn Mower Pro · United States (multiple hotel chains)

Failure Mode

MALFUNCTION

Event Date

May 11, 2026

Primary Entity

Yarbo

Robotic Platform

Yarbo Lawn Mower Pro

Jurisdiction / Location

United States (multiple hotel chains)

Audit Standard

Physical State Verified

Incident Abstract & Audit Findings

Security researcher Andreas Makris discovered a cluster of vulnerabilities in Yarbo yard robots including hardcoded root passwords shared across all devices, weak MQTT messaging security, and persistent remote tunnel backdoors. The flaws allowed attackers to remotely hijack the worldwide robot fleet, access GPS coordinates, Wi-Fi passwords, and camera feeds, and bypass the emergency stop button on a mower with controllable blades.

System & Fleet Architecture

Operating Manufacturer

Hardware Platform

Yarbo Lawn Mower ProView Spec

Operational Sectors

Physical AI / Robotics

Primary Sources & Evidentiary Filings

  • https://www.malwarebytes.com/blog/news/2026/05/yarbo-responds-to-robot-flaws-that-could-mow-down-their-owners

    https://www.malwarebytes.com/blog/news/2026/05/yarbo-responds-to-robot-flaws-that-could-mow-down-their-owners

  • https://www.sentinelone.com/vulnerability-database/cve-2026-10557/

    https://www.sentinelone.com/vulnerability-database/cve-2026-10557/

Related Incidents & Failure Precedents

6 records on file

Incident Context & FAQ

What happened in Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?

Security researcher Andreas Makris discovered a cluster of vulnerabilities in Yarbo yard robots including hardcoded root passwords shared across all devices, weak MQTT messaging security, and persistent remote tunnel backdoors. The flaws allowed attackers to remotely hijack the worldwide robot fleet, access GPS coordinates, Wi-Fi passwords, and camera feeds, and bypass the emergency stop button on a mower with controllable blades. Makris demonstrated the risk by having his Yarbo mower run him over. Yarbo responded by disabling remote diagnostic tunnels, resetting root passwords, locking down unauthenticated endpoints, and promising structural changes including unique per-device credentials and OTA credential rotation. CVE-2026-10557 was assigned.

When did this incident occur?

The incident is recorded as occurring on May 11, 2026 on the DEPLOY registry. The date reflects the underlying real-world event, not the registry record's creation date.

What robot was involved in Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?

Yarbo Lawn Mower Pro by Yarbo is the recorded robot involved in this incident at United States (multiple hotel chains).

Has anyone responded to Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?

No responses to this incident are recorded on the DEPLOY registry. Operators, manufacturers, or affected parties can submit responses to the editorial team; absence is not a guarantee no response was issued.

What is the current status of Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?

This incident is an active record on the DEPLOY registry; no retraction or correction has been issued.