Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Overview
Security researcher Olivier Laflamme has reported two serious vulnerabilities in the Unitree G1 EDU humanoid robot that allow for root remote code execution (RCE). The vulnerabilities, identified as CVE-2026-76639 and CVE-2026-76640, can be exploited through different paths, including a Bluetooth Low Energy (BLE) method that can give attackers root access to the robot’s Locomotion PC. The first vulnerability involves a network-adjacent route via components called chat_go and bashrunner. This is a significant concern for users of the Unitree G1 EDU, as it opens the door for unauthorized control of the robot, potentially leading to malicious activities. Addressing these flaws is crucial for ensuring the security and reliability of robotic systems, especially in educational and research environments where they are increasingly being used.
Key Takeaways
- Affected Systems: Unitree G1 EDU humanoid robot; vulnerabilities tracked as CVE-2026-76639 and CVE-2026-76640.
- Action Required: Users should apply security patches as they become available from Unitree and consider disabling Bluetooth functionality if not in use to mitigate potential exploitation.
- Timeline: Newly disclosed
Original Article Summary
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the
Impact
Unitree G1 EDU humanoid robot; vulnerabilities tracked as CVE-2026-76639 and CVE-2026-76640.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Users should apply security patches as they become available from Unitree and consider disabling Bluetooth functionality if not in use to mitigate potential exploitation.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, RCE.