Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [cve, unitree, g1-edu, humanoid-robot, bluetooth-le, rce, iot, critical] ยท confidence: medium ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false

CVE-2026-76640

CVE-2026-76640 is one of two critical flaws disclosed in the Unitree G1 EDU humanoid robot on 28 August 2026. It enables a root remote-code-execution chain beginning from Bluetooth Low Energy (BLE) proximity, meaning an attacker within wireless range of the robot can escalate to full root control without prior authentication.

Unitree's guidance at the time of disclosure did not identify a confirmed fixed firmware release for either G1 EDU flaw. Organisations deploying humanoid robots or robotics research platforms should treat the devices as untrusted until patched firmware is available, and disable BLE interfaces where they are not required for operations.

Source

  • raw/digests/Cyber-Digest-2026-08-30.md โ€” Unitree G1 EDU 'Also notable' disclosure note (Global (Macro) sector report)