PT-2026-22178 · Eclipse+1 · Eclipse Cyclonedds+1

Olivier Laflamme

+1

·

Published

2026-02-26

·

Updated

2026-06-16

·

CVE-2026-27509

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unitree Go2 versions V1.1.7 through V1.1.9 Unitree Go2 version V1.1.11 (EDU)
Description Lack of DDS authentication and authorization for the Eclipse CycloneDDS topic "rt/api/programming actuator/request" handled by actuator manager.py allows a network-adjacent, unauthenticated attacker to join DDS domain 0. By publishing a crafted message with the variable api id=1002 containing arbitrary Python code, the attacker can cause the robot to write this code to the disk under /unitree/etc/programming/ and bind it to a physical controller keybinding. Once the keybinding is pressed, the code executes with root privileges, and the binding remains active after reboots.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27509

Affected Products

Eclipse Cyclonedds
Unitree Go2