RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / Unitree / 2026-08-27

Two root RCE flaws (CVE-2026-76639/76640) disclosed in Unitree G1 EDU

S1 · 08/27
2026 · Unitree

Record

CompanyUnitree
Categoryhumanoid
Typecyber
Date08/27
2026
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
SeverityS1 (near-miss / disclosed vulnerability)
Scalefleet-wide (G1 EDU model)
Confidencehigh
VerificationCited source on file; not independently re-verified
SourceThe Hacker News

What happened

A security researcher disclosed two chained remote-code-execution vulnerabilities in the Unitree G1 EDU humanoid -- one network-adjacent via chat_go/bashrunner, one via Bluetooth proximity plus a Wi-Fi provisioning buffer overflow -- together allowing unauthenticated root access to any G1 within Bluetooth range, with no confirmed fixed firmware publicly verified at disclosure.

Unitree record context

Entries by year and severity

232025 S1: 22025 S2: 13252026 S1: 12026 S3: 1226
S1S2S3S4S5

By incident type

By severity

Unitree vs humanoid alternatives

humanoid context

humanoid: entries by year

482017 S1: 11172024 S1: 11242025 S1: 22025 S2: 12025 S3: 12025 S5: 48252026 S1: 12026 S3: 1226
S1S2S3S4S5

humanoid: failure modes

humanoid: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Comparable cyber events in humanoid

SevDateCompanyEvent
S12025-10UnitreeUnauthenticated RCE flaws (CVE-2026-27509, CVE-2026-27510) found in Unitree Go2
S22025-09UnitreeUniPwn wormable Bluetooth exploit roots Unitree Go2, B2, G1 and H1
S2UnitreeBackdoor (CVE-2025-2894) found in Unitree Go1 robot firmware

Other Unitree entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs