_Incident · Malfunction_

# Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass

Canonical ID: `66aa9619-89d9-416c-9cec-5d821c6226c2`

- **Occurred:** 2026-05-11
- **Kind:** `malfunction`
- **Status (derived):** active
- **Model:** [Yarbo Lawn Mower Pro](/models/yarbo-lawn-mower-pro.md) (id: `b910a007-e2b9-4bbe-aef2-9ad96c0d437d`)
- **Company:** [Yarbo](/companies/yarbo.md)
- **Category:** [Lawn mowers](/lawn-mowers)

Security researcher Andreas Makris discovered a cluster of vulnerabilities in [Yarbo](/companies/yarbo.md) yard robots including hardcoded root passwords shared across all devices, weak MQTT messaging security, and persistent remote tunnel backdoors. The flaws allowed attackers to remotely hijack the worldwide robot fleet, access GPS coordinates, Wi-Fi passwords, and camera feeds, and bypass the emergency stop button on a mower with controllable blades. Makris demonstrated the risk by having his Yarbo mower run him over. Yarbo responded by disabling remote diagnostic tunnels, resetting root passwords, locking down unauthenticated endpoints, and promising structural changes including unique per-device credentials and OTA credential rotation. CVE-2026-10557 was assigned.

## Sources (2)

1. **Malwarebytes** · https://www.malwarebytes.com/blog/news/2026/05/yarbo-responds-to-robot-flaws-that-could-mow-down-their-owners · 2026-05-11
2. **SentinelOne CVE Database** · https://www.sentinelone.com/vulnerability-database/cve-2026-10557/ · 2026-05-11

## Status history

- **active** · 2026-07-29 · agent:recon

## Common questions

### What happened in Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?

Security researcher Andreas Makris discovered a cluster of vulnerabilities in Yarbo yard robots including hardcoded root passwords shared across all devices, weak MQTT messaging security, and persistent remote tunnel backdoors. The flaws allowed attackers to remotely hijack the worldwide robot fleet, access GPS coordinates, Wi-Fi passwords, and camera feeds, and bypass the emergency stop button on a mower with controllable blades. Makris demonstrated the risk by having his Yarbo mower run him over. Yarbo responded by disabling remote diagnostic tunnels, resetting root passwords, locking down unauthenticated endpoints, and promising structural changes including unique per-device credentials and OTA credential rotation. CVE-2026-10557 was assigned.

### When did this incident occur?

The incident is recorded as occurring on May 11, 2026 on the DEPLOY registry. The date reflects the underlying real-world event, not the registry record's creation date.

### What robot was involved in Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?

Yarbo Lawn Mower Pro is the recorded robot involved in this incident.

### Has anyone responded to Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?

No responses to this incident are recorded on the DEPLOY registry. Operators, manufacturers, or affected parties can submit responses to the editorial team; absence is not a guarantee no response was issued.

### What is the current status of Security researcher reveals Yarbo yard robots vulnerable to remote hijacking, camera access, and emergency-stop bypass?

This incident is an active record on the DEPLOY registry; no retraction or correction has been issued.


_API: GET /v1/incidents/66aa9619-89d9-416c-9cec-5d821c6226c2 · sources: /v1/incidents/66aa9619-89d9-416c-9cec-5d821c6226c2/sources · responses: /v1/incidents/66aa9619-89d9-416c-9cec-5d821c6226c2/responses · status: /v1/incidents/66aa9619-89d9-416c-9cec-5d821c6226c2/status · canonical URL: /incidents/yarbo-robot-security-vulnerabilities-2026-05_
