type: vulnerability ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [cve, unitree, g1-edu, humanoid-robot, chat_go, bashrunner, rce, iot, critical] ยท confidence: medium ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false
CVE-2026-76639
CVE-2026-76639 is one of two critical flaws disclosed in the Unitree G1 EDU humanoid robot on 28 August 2026. It is a network-adjacent root remote-code-execution chain affecting the robot's chat_go and bashrunner interfaces, allowing an attacker on the local network to execute arbitrary commands as root on the robot.
No confirmed fixed firmware release had been identified in Unitree guidance at the time of disclosure. Operators should isolate G1 EDU robots from general-purpose networks and disable remote service interfaces until a fix is confirmed.
Source
- raw/digests/Cyber-Digest-2026-08-30.md โ Unitree G1 EDU 'Also notable' disclosure note (Global (Macro) sector report)