CVE-2026-27509Disclosure(unitree / go2)

MEDIUMCVSS 8.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for unitree go2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join DDS domain 0 and publish a crafted message (api_id=1002) containing arbitrary Python, which the robot writes to disk under /unitree/etc/programming/ and binds to a physical controller keybinding. When the keybinding is pressed, the code executes as root and the binding persists across reboots.

4.3/ 10 priority

Sources & remediation

Exploit / PoC references
Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go2
  • go2_edu
  • go2_edu_firmware
  • go2_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 21 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 10 signals
  • Technical details provided in 16 signals
  • Disclosure: 14 classified signals
  • General: 1 classified signal
  • Peaked 9d ago at 6 mentions (2026-02-27); latest day: 1
  • 21 total mentions across 11 days

Affected systems

Vendors
Products
go2go2_edugo2_edu_firmwarego2_firmware

2 versions affected across 4 products

Deep dive

Activity timeline21 mentions / 11d
02356Mentions · 2026-02-26: 5Mentions · 2026-02-27: 6Mentions · 2026-02-28: 2Mentions · 2026-03-03: 1Mentions · 2026-03-13: 1Mentions · 2026-03-17: 1Mentions · 2026-05-14: 1Mentions · 2026-06-15: 1Mentions · 2026-07-17: 1Mentions · 2026-08-21: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-02-26: 1PoC Mentioned / Linked · 2026-02-27: 2PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-27: 1Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-08-21: 1Technical Details · 2026-02-26: 4Technical Details · 2026-02-27: 4Technical Details · 2026-02-28: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-17: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-15: 1Technical Details · 2026-08-21: 102-2602-2702-2803-0303-1303-1705-1406-1507-1708-2108-27
Signal classification4 categories
Disclosure
1466.7%
PoC
523.8%
General
14.8%
Exploit
14.8%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-265
Disclosure5
2026-02-276
Disclosure5General1
2026-02-282
Disclosure1PoC1
2026-03-031
Disclosure1
2026-03-131
Disclosure1
2026-03-171
PoC1
2026-05-141
PoC1
2026-06-151
PoC1
2026-07-171
PoC1
2026-08-211
Exploit1
2026-08-271
Disclosure1
Full discourse20 posts
  • 0xor0ne@0xor0ne
    PoC

    Reverse engineering and exploiting Unitree GO2 robots (CVE-2026-27509 / CVE-2026-27510). http://boschko.ca/unitree-go2-rce/ Research by @olivier_boschko and @ruikai #infosec https://t.co/nHEmQQ5xbU

    Post summary

    Researchers reverse‑engineered Unitree GO2 robots, exposed CVE‑2026‑27509/27510, and released a PoC exploit (RCE) via a linked website.

    2170121607.7K
    93.6K followersView on X
  • Boschko@olivier_boschko
    Disclosure

    Discovered 2 RCEs in Unitree Go2 with @ruikai. CVE-2026-27509 is unauth'd over DDS. CVE-2026-27510 is the same sink, different source. Dropped the 32-minute technical writeup from unboxing to shells. Hope you enjoy the read! ❤️ https://boschko.ca/unitree-go2-rce

    Post summary

    Two unauthenticated RCEs were discovered in the Unitree Go2 robot, with a technical writeup and PoC linked for further details.

    32821003910.8K
    4.3K followersView on X
  • 0xor0ne@0xor0ne
    PoC

    Arbitrary Python execution as root on Unitree GO2 robots via unauthenticated DDS and mobile DB tampering (CVE-2026-27509 and CVE-2026-27510) https://boschko.ca/unitree-go2-rce/ Research by @olivier_boschko and @ruikai #infosec https://t.co/jyojjlVZbr

    Post summary

    Researchers disclosed that Unitree GO2 robots can be compromised to execute arbitrary Python as root through unauthenticated DDS and mobile DB tampering, and a PoC is available at the provided link.

    017191476.7K
    88.1K followersView on X
  • 0xor0ne@0xor0ne
    PoC

    Great work by by @olivier_boschko and @ruikai about getting root RCE on Unitree GO2 robots via unauthenticated DDS and mobile DB tampering (CVE-2026-27509 and CVE-2026-27510) https://boschko.ca/unitree-go2-rce/ #infosec https://t.co/qOg7V33Idk

    Post summary

    A proof‑of‑concept demonstrates root remote code execution on Unitree GO2 robots via unauthenticated DDS and mobile DB tampering (CVE‑2026‑27509/27510); no patch or active exploitation is reported.

    09075334.9K
    88.7K followersView on X
  • 0xor0ne@0xor0ne
    PoC

    Root RCE on Unitree GO2 robots via unauthenticated DDS and mobile DB tampering (CVE-2026-27509 / CVE-2026-27510). Work by @olivier_boschko and @ruikai http://boschko.ca/unitree-go2-rce/ #infosec https://t.co/pC8UWRMwKp

    Post summary

    A new root remote code execution vulnerability (CVE-2026-27509/27510) has been disclosed for Unitree GO2 robots, exploiting unauthenticated DDS and mobile DB tampering, with a publicly shared PoC available.

    011067274.4K
    92.2K followersView on X
  • 0xor0ne@0xor0ne
    PoC

    Unauthenticated DDS access and mobile DB tampering get you root RCE on Unitree GO2 robots (CVE-2026-27509 / CVE-2026-27510). Teardown by @olivier_boschko and @ruikai http://boschko.ca/unitree-go2-rce/ #infosec https://t.co/vr376mBpNK

    Post summary

    The tweet announces a new Root RCE flaw in Unitree GO2 robots, linking to a teardown that presumably includes a proof‑of‑concept, but offers no evidence of active exploitation or available patches.

    212063264.8K
    93.0K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/

    Post summary

    The post announces two remote code execution vulnerabilities (CVE-2026-27509 and CVE-2026-27510) affecting Unitree robots, with a link to further details.

    1501461.3K
    32.7K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Exploit

    From DDS Packets to Robot Shells: Two Unauthenticated root RCEs in Unitree Robots One is fully unauthenticated over the network. One requires only local database access on the companion app. - CVE-2026-27509: Unauthenticated DDS topic to arbitrary Python as root - CVE-2026-27510: Tamper the Android app’s Blockly database to same root execution path Both execute as root and persist across reboots. the complete technical analysis and public exploits & public PoCs just dropped. - http://github.com/OlivierLaflamme/UnitreeRCE

    Post summary

    The post discloses two unauthenticated root RCE CVEs in Unitree robots, provides technical details, and supplies publicly released PoCs and exploit code via a GitHub link.

    000951.8K
    57.3K followersView on X
  • 7h3h4ckv157@7h3h4ckv157
    Disclosure

    CVE-2026-27509 Unauthenticated DDS-Based Remote Code Execution & CVE-2026-27510 Mobile Database Tampering Leading to Remote Code Execution Cool work by @olivier_boschko Read: https://boschko.ca/unitree-go2-rce https://t.co/JTZ4ZUtm7U

    Post summary

    The tweet announces the existence of CVE-2026-27509 and CVE-2026-27510, referencing a linked write‑up that presumably contains technical and PoC details, but does not discuss exploitation, patches, or mitigations.

    020232.2K
    57.1K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Unitree社の四足歩行ロボットGo2に2件のリモートコード実行(RCE)脆弱性(CVE-2026-27509、CVE-2026-27510)が存在した。両脆弱性とも設計上の認証・検証不足に起因し、ロボットを完全に制御される重大な問題である。 最初の脆弱性は、DDS(Data Distribution Service)通信に認証が実装されていない点を悪用するものだ。攻撃者は同一ネットワーク上から特定のDDSトピックに細工したメッセージを送信し、Pythonコードをアップロードできる。さらに、そのコードをコントローラーの特定キー(例:R1+Y)に紐づけることで、ボタン操作をきっかけに任意コードをroot権限で実行させられる。コードはロボット内部に保存されるため、再起動後も持続するバックドアとなる。 二つ目の脆弱性は、ファームウェア更新後にDDSトピックの列挙が制限された環境下でも成立する。公式AndroidアプリのローカルSQLiteデータベース内に保存されるプログラム情報を改ざんし、Pythonコード部分(pyCode)を書き換えることで、同様に任意コード実行が可能となる。ユーザーはアプリ上でプログラムをキーに割り当てるだけで、改ざん済みコードが実行される。 https://boschko.ca/unitree-go2-rce/

    Post summary

    The text discloses two remote code execution vulnerabilities in Unitree Go2 robots, detailing authentication weaknesses, exploitation via DDS and app database manipulation, enabling persistent root-level code execution.

    020501.3K
    11.6K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/

    Post summary

    The brief headline announces two remote code execution vulnerabilities (CVE‑2026‑27509 and CVE‑2026‑27510) affecting Unitree Robots, with a link to further details.

    00021909
    151.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-27509 Unauthenticated DDS-Based Remote Code Execution CVE-2026-27510 Mobile Database Tampering Leading to Remote Code Execution From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/

    Post summary

    A blog post discloses two RCE vulnerabilities (CVE-2026-27509 and CVE-2026-27510) in Unitree robots, providing a link likely containing PoC details, but no evidence of active exploitation or patch information.

    00011376
    6.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2026-20127 3 - CVE-2025-59536 4 - CVE-2026-27509 5 - CVE-2026-27739 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists five trending CVEs without providing additional technical or operational details.

    00020314
    1.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Unitree Go2, Missing Authentication, #CVE-2026-27509 (High) https://dailycve.com/unitree-go2-missing-authentication-cve-2026-27509-high/

    Post summary

    The text announces the high‑severity CVE-2026-27509 for Unitree Go2, highlighting a missing authentication flaw without providing PoC, exploit, or patch information.

    0000051
    168 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27509 (CVSS:8.5, HIGH) is Awaiting Analysis. Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) do not implement DDS authentication or authorizati..https://nvd.nist.gov/vuln/detail/CVE-2026-27509 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27509, highlighting its high severity and the absence of DDS authentication in certain Unitree Go2 firmware versions, but it does not provide evidence of exploitation or mitigation.

    0000041
    173 followersView on X
  • CybrPulse@CybrPulse
    Disclosure

    Two RCEs just dropped for Unitree Go2 robots. Unauthenticated remote code execution on a quadrupedal robot. That's... not great. CVE-2026-27509 & CVE-2026-27510 https://boschko.ca/unitree-go2-rce/

    Post summary

    Two unauthenticated remote code execution vulnerabilities (CVE-2026-27509 & CVE-2026-27510) have been disclosed for Unitree Go2 robots, with details posted on a blog.

    0000040
    16 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-27509 - High Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request... https://www.thehackerwire.com/vulnerability/CVE-2026-27509/ https://t.co/FupafLb7CK

    Post summary

    The post announces CVE-2026-27509 in Unitree Go2 firmware, noting missing DDS authentication that could permit unauthorized access, with no PoC, exploit, or patch mentioned.

    0000061
    119 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27509 Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/pro… https://www.cve.org/CVERecord?id=CVE-2026-27509 ----- Traducción: CVE-2026-27509 Uni… http://infoflow.cloud`

    Post summary

    CVE-2026-27509 exposes Unitree Go2 firmware versions lacking DDS authentication/authorization on a CycloneDDS topic, potentially allowing unauthorized access to the device.

    0000050
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27509 Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/pro… https://www.cve.org/CVERecord?id=CVE-2026-27509

    Post summary

    The Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) lack DDS authentication/authorization for the Eclipse CycloneDDS topic rt/api/pro, exposing a potential security risk.

    000001.5K
    56.6K followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/ https://t.co/a4A0ffoJ5t

    Post summary

    The tweet announces the discovery of two remote code execution vulnerabilities in Unitree robots, linking to a blog post for further details.

    0000086
    440 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWunitreego2---
HWunitreego2_edu---
OSunitreego2_edu_firmware1.1.11--
OSunitreego2_firmware---

Explore more