PT-2026-22178 · Eclipse+1 · Eclipse Cyclonedds+1
Olivier Laflamme
+1
·
Published
2026-02-26
·
Updated
2026-06-16
·
CVE-2026-27509
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Unitree Go2 versions V1.1.7 through V1.1.9
Unitree Go2 version V1.1.11 (EDU)
Description
Lack of DDS authentication and authorization for the Eclipse CycloneDDS topic "rt/api/programming actuator/request" handled by
actuator manager.py allows a network-adjacent, unauthenticated attacker to join DDS domain 0. By publishing a crafted message with the variable api id=1002 containing arbitrary Python code, the attacker can cause the robot to write this code to the disk under /unitree/etc/programming/ and bind it to a physical controller keybinding. Once the keybinding is pressed, the code executes with root privileges, and the binding remains active after reboots.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Cyclonedds
Unitree Go2