As of the disclosure date, no patch information has been provided by Unitree. Organizations using the G1 EDU should monitor Unitree's official channels for firmware updates and security advisories. Until a patch is available, consider restricting network access to the robot and disabling Bluetooth when not in use. Additionally, ensure the robot is deployed in a controlled environment to minimize the risk of unauthorized physical or network access.
Quick answers
What is CVE-2026-76640?
As of the disclosure date, no patch information has been provided by Unitree. Organizations using the G1 EDU should monitor Unitree's official channels for firmware updates and security advisories. Until a patch is available, consider restricting network access to the robot and disabling Bluetooth when not in use. Additionally, ensure the robot is deployed in a controlled environment to minimize the risk of unauthorized physical or network access.
How severe is CVE-2026-76640?
critical
Is CVE-2026-76640 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-76640 be mitigated?
As of the disclosure date, no patch information has been provided by Unitree. Organizations using the G1 EDU should monitor Unitree's official channels for firmware updates and security advisories. Until a patch is available, consider restricting network access to the robot and disabling Bluetooth when not in use. Additionally, ensure the robot is deployed in a controlled environment to minimize the risk of unauthorized physical or network access.
CVSS
—
Vendor
Unitree
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
G1 EDU
Mitigation
As of the disclosure date, no patch information has been provided by Unitree. Organizations using the G1 EDU should monitor Unitree's official channels for firmware updates and security advisories. Until a patch is available, consider restricting network access to the robot and disabling Bluetooth when not in use. Additionally, ensure the robot is deployed in a controlled environment to minimize the risk of unauthorized physical or network access.
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU humanoid robot. The vulnerabilities, tracked as CVE-2026-76639 and CVE-2026-76640, allow an attacker to achieve root-level access on the robot's Locomotion PC. One chain is exploitable over Bluetooth Low Energy (BLE), while the other uses a network-adjacent path through the chat_go and bashrunner components. Successful exploitation could let an attacker take full control of the robot, potentially causing physical harm. Patch information is not yet available.