Security researcher Olivier Laflamme has revealed two distinct root remote code execution (RCE) vulnerabilities impacting the Unitree G1 EDU humanoid robot. These flaws, tracked as CVE-2026-76639 and CVE-2026-76640, enable attackers to achieve root access on the robot's Locomotion PC. The disclosure was made on August 27, 2026, detailing the separate attack paths.
CVE-2026-76639 involves a network-adjacent path that exploits a path-traversal condition in 'chat_go' to reach 'bashrunner', leading to root code execution. CVE-2026-76640 begins with a Bluetooth Low Energy (BLE) write path that accepts bootstrap interaction without requiring Bluetooth pairing. This BLE chain, combined with a buffer overflow in Wi-Fi provisioning code, also results in root execution on the Locomotion PC. Laflamme noted that a cloud authorization fix implemented by Unitree in July 2026 addresses a specific cloud account-to-robot ownership check that was part of the original proof-of-concept for the BLE vulnerability.
The existence of these unpatched vulnerabilities means Unitree G1 EDU owners are currently exposed to potential unauthorized control of their robots. As of the disclosure date, Unitree has not verified an exact fixed firmware release in any accessible guidance, leaving users without a clear timeline or target for remediation. The cloud authorization fix only addresses one component of the BLE chain, and the core vulnerabilities remain.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researcher Olivier Laflamme disclosed two independent root remote code execution (RCE) vulnerabilities, CVE-2026-76639 and CVE-2026-76640, affecting the Unitree G1 EDU humanoid robot. One flaw can be exploited network-adjacent, and the other starts over Bluetooth Low Energy (BLE), allowing attackers to gain root access on the robot's Locomotion PC. These vulnerabilities pose a risk to G1 EDU owners as Unitree has not yet confirmed a fixed firmware release, leaving robots susceptible to unauthorized control.