Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Unitree G1 Humanoid Robot Vulnerable to Remote Root via Bluetooth, Cloud API, and Path‑Traversal (CVE‑2026‑76639/76640)

A researcher chained two newly disclosed CVEs to gain unauthenticated root on Unitree G1 robots, exposing a control gap that SOC 2 audits target. Continuous control mapping and evidence collection are essential to demonstrate remediation.

LiveThreat™ Intelligence · 📅 August 29, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Hack One Robot, Reach the Next: Unitree G1 Humanoid Robot Exposes Remote Root via Bluetooth, Cloud API, and Path‑Traversal Flaws

What Happened – Security researcher Olivier Laflamme disclosed two new CVEs (CVE‑2026‑76639, CVE‑2026‑76640) in the Unitree G1 humanoid robot. By chaining a Bluetooth write‑without‑pairing flaw, an insecure cloud‑API decryption oracle, and a path‑traversal bug in the robot’s AI‑chatbot service, an attacker can obtain unauthenticated root access to any G1 within Bluetooth range and execute arbitrary code on the device.

Why It Matters for Compliance & Audit Readiness

  • The chain demonstrates a classic control‑gap: lack of proper authentication and validation across firmware, cloud services, and wireless interfaces – a scenario SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) are designed to detect and mitigate.
  • Continuous evidence of control enforcement (e.g., immutable firmware signing, Bluetooth access logs, API request validation) is required to prove “least‑privilege” and “secure configuration” commitments during a SOC 2 audit.
  • Verisq’s Control Mapping capability can automatically map these technical findings to the relevant SOC 2 criteria and collect ongoing proof that remediation controls remain effective.

Who Is Affected – Manufacturers and integrators deploying Unitree G1 robots in logistics, warehousing, research labs, and other industrial automation environments.

Recommended Actions

  • Map the Bluetooth‑authentication, cloud‑API validation, and file‑upload controls to SOC 2 CC6.1 and CC7.1.
  • Deploy immutable firmware signing and enforce strict file‑name validation on the chatbot service.
  • Enable continuous logging of Bluetooth connections and cloud‑API calls; feed logs into a SOC 2‑ready evidence store.
  • Conduct a rapid patch rollout for CVE‑2026‑76639/76640 and verify remediation through automated compliance scans.

Source: Security Affairs

Technical Notes –

  • Attack vector: Bluetooth write‑without‑pairing → cloud decryption oracle → unauthenticated AES‑128 key → Wi‑Fi config abuse → path‑traversal file write → root shell.
  • CVE‑2026‑76639: Unauthenticated Bluetooth characteristic write.
  • CVE‑2026‑76640: Path‑traversal in AI‑chatbot “knowledge” upload, leading to arbitrary file write and privilege escalation.
  • Data at risk: Firmware integrity, robot control commands, potentially any downstream system the robot interfaces with.
📰 Original Source
https://securityaffairs.com/198085/hacking/hack-one-robot-reach-the-next-unitree-g1-security-flaws.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →