All incidents

Unitree G1 robot flaws (CVE-2026-76639, CVE-2026-76640) enable remote root

vulnerabilityopenAug 28, 2026 — Aug 29, 2026
Hacker exploits Unitree G1 robot via upload and Bluetooth flaw

A security researcher, Olivier Laflamme, has demonstrated how two flaws in the Unitree G1 humanoid robot can be chained to gain full remote control without needing physical access to the machine.

Olivier Laflamme disclosed the issues after finding that the robot accepts unsafe file uploads over its Ethernet port and that its Bluetooth implementation leaks a decryption key from Unitree’s cloud service.

The first flaw tracked as CVE-2026-76639 carries a CVSS score of 8.8 and allows an attacker to upload a malicious file to the robot’s Ethernet interface, which then executes with root privileges.

The second flaw recorded as CVE-2026-76640 scores 7.7 and abuses the Bluetooth unpairing process to retrieve a decryption key that Unitree uses to authenticate with its cloud, granting the attacker control over any nearby G1 that shares the same key.

By first uploading a crafted payload via Ethernet the attacker gains a shell on the robot, then triggers the Bluetooth unpairing flaw to extract the cloud key, which can be reused to impersonate the robot and send commands to other units within radio range.

This chaining means that a single compromised robot can act as a pivot to infect others that are physically close, raising the risk of a chain reaction in dense deployments.

Security coverage of the research highlighted that no threat actors have been observed exploiting these flaws in the wild, but the proof‑of‑concept shows how a swarm of G1 robots could be compromised simultaneously.

Unitree has released firmware updates that address both vulnerabilities and advises customers to apply them immediately.

Defenders should start by applying the latest firmware from Unitree, which patches the Ethernet upload flaw and the Bluetooth key leakage issue.

They should also restrict Ethernet access to trusted management networks and disable Bluetooth pairing unless it is explicitly required for operation.

Monitoring logs for unexpected file uploads and for Bluetooth unpairing events can help detect an attempted compromise before it spreads.

Network segmentation that isolates robots from corporate IT limits the impact of a compromised unit, while strong mutual authentication between robots and the cloud prevents key reuse.

Maintaining an accurate inventory of all G1 devices and subscribing to Unitree’s security advisories ensures that future patches are applied promptly.

Intelligence briefing updated Aug 29, 2026

CVE-2026-76639 8.8 CVE-2026-76640 7.7
Root sourceboschko.ca
Timeline Coverage

Swipe to explore timeline