PT-2026-22178 · Eclipse+1 · Eclipse Cyclonedds+1

·

CVE-2026-27509

·

Published

2026-02-26

·

Updated

2026-08-27

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unitree Go2 versions V1.1.7 through V1.1.9 Unitree Go2 version V1.1.11 (EDU)
Description Lack of DDS authentication and authorization for the Eclipse CycloneDDS topic 'rt/api/programming actuator/request' handled by actuator manager.py allows a network-adjacent, unauthenticated attacker to join DDS domain 0. By publishing a crafted message using the api id variable set to 1002, the attacker can send arbitrary Python code. The robot writes this code to the disk at /unitree/etc/programming/ and binds it to a physical controller keybinding. When the keybinding is triggered, the code executes with root privileges, and the binding remains active after reboots.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27509

Affected Products

Eclipse Cyclonedds
Unitree Go2