Incident · Malfunction
Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass
Security researcher Andreas Makris discovered a cluster of vulnerabilities in Yarbo yard robots including hardcoded root passwords shared across all devices, weak MQTT messaging security, and persistent remote tunnel backdoors. The flaws allowed attackers to remotely hijack the worldwide robot fleet, access GPS coordinates, Wi-Fi passwords, and camera feeds, and bypass the emergency stop button on a mower with controllable blades.
Makris demonstrated the risk by having his Yarbo mower run him over. Yarbo responded by disabling remote diagnostic tunnels, resetting root passwords, locking down unauthenticated endpoints, and promising structural changes including unique per-device credentials and OTA credential rotation. CVE-2026-10557 was assigned.
Occurred 2026-05-11 · Yarbo Lawn Mower Pro · Yarbo · Lawn mowers
How to read this record
Incident records on DEPLOY are compiled from public sources (regulatory filings, news reports, and operator disclosures) and reflect what has been reported and tracked to date. They are not legal findings, determinations of fault, or safety ratings, and may be updated as new information is verified. See the sources below for the underlying references.Machine-readable surfaces
- Markdown mirror: /incidents/yarbo-robot-security-vulnerabilities-2026-05.md
- JSON-LD: embedded in this page’s head
- REST API: /v1/incidents/66aa9619-89d9-416c-9cec-5d821c6226c2
- Data documentation: /data
- Query this programmatically: Deploy MCP
Sources (2)
- Malwarebytes · https://www.malwarebytes.com/blog/news/2026/05/yarbo-responds-to-robot-flaws-that-could-mow-down-their-owners · 2026-05-11
- SentinelOne CVE Database · https://www.sentinelone.com/vulnerability-database/cve-2026-10557/ · 2026-05-11
Status history
- Active · 2026-07-29 · agent:recon
Common questions
What happened in Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?
When did this incident occur?
What robot was involved in Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?
Has anyone responded to Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?
What is the current status of Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?
Methodology: Verified · 2 sources (no primary) · last reviewed 2026-08-09
Verification posture
Verified
Low confidence
Review state
Stable
Last reviewed 2026-08-09
Sources by quality tier
- 2
- unclassified
- Unclassified source
The framework is documented at /methodology. Corrections at /corrections. Reviewer: DEPLOY editorial team.
Methodology surface for Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass.Deploy Watch
Track this incident.
We notify you when the regulator updates the record, the remedy status changes, or a related incident surfaces.
Canonical ID 66aa9619-89d9-416c-9cec-5d821c6226c2