← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Two Root RCE Flaws Disclosed in Unitree G1 EDU Humanoid Robot, One Via Bluetooth

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two root RCE flaws (CVE-2026-76639, CVE-2026-76640) found in Unitree G1 EDU.
  • One RCE path is network-adjacent, the other starts via Bluetooth.
  • Flaws allow root access to the robot's Locomotion PC.
  • No confirmed fixed firmware release from Unitree yet.

Discovery of Critical Vulnerabilities

Security researcher Olivier Laflamme has revealed two distinct root remote code execution (RCE) vulnerabilities impacting the Unitree G1 EDU humanoid robot. These flaws, tracked as CVE-2026-76639 and CVE-2026-76640, enable attackers to achieve root access on the robot's Locomotion PC. The disclosure was made on August 27, 2026, detailing the separate attack paths.

Technical Details of the Exploits

CVE-2026-76639 involves a network-adjacent path that exploits a path-traversal condition in 'chat_go' to reach 'bashrunner', leading to root code execution. CVE-2026-76640 begins with a Bluetooth Low Energy (BLE) write path that accepts bootstrap interaction without requiring Bluetooth pairing. This BLE chain, combined with a buffer overflow in Wi-Fi provisioning code, also results in root execution on the Locomotion PC. Laflamme noted that a cloud authorization fix implemented by Unitree in July 2026 addresses a specific cloud account-to-robot ownership check that was part of the original proof-of-concept for the BLE vulnerability.

Impact and Lack of Patch Information

The existence of these unpatched vulnerabilities means Unitree G1 EDU owners are currently exposed to potential unauthorized control of their robots. As of the disclosure date, Unitree has not verified an exact fixed firmware release in any accessible guidance, leaving users without a clear timeline or target for remediation. The cloud authorization fix only addresses one component of the BLE chain, and the core vulnerabilities remain.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Aug 28

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security researcher Olivier Laflamme disclosed two independent root remote code execution (RCE) vulnerabilities, CVE-2026-76639 and CVE-2026-76640, affecting the Unitree G1 EDU humanoid robot. One flaw can be exploited network-adjacent, and the other starts over Bluetooth Low Energy (BLE), allowing attackers to gain root access on the robot's Locomotion PC. These vulnerabilities pose a risk to G1 EDU owners as Unitree has not yet confirmed a fixed firmware release, leaving robots susceptible to unauthorized control.