Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Safety · Co-dominant path
Device-control safety
Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.
Proximity or local access
carrying api_id is 1002 arbitrary Python executed as root via subprocess in the actuator_manager path.
EvidenceNVD
Cross-domain authority chain
Crosses network and device and physical and safety boundaries and remote code execution and persistence is a reusable bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Persistence via hotkey-bound scripts surviving reboot, must be manually cleared from and unitree and etc and programming and.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
carrying api_id is 1002 arbitrary Python executed as root via subprocess in the actuator_manager path.
- Execution complexity
EC 3 - Reproducible exploit workflow
Researcher published full repro, without authentication bypass needed.
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.
- Data / perception
DP 3 - Sensitive device or personal data
Root code execution exposes the robot's motion commands, actuator state, and connected sensor state as part of the control path.
- Authority
AT 3 - Administrative or command authority
Remote code execution reaches operating-system and robot-service authority, including motion control, but not the firmware-signing root.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Crosses network and device and physical and safety boundaries and remote code execution and persistence is a reusable bridge.
- Reuse scale
SR 3 - Portable product-class technique
Identical flaw reuses across all affected firmware (technique and artifact portability) but no shared secret and key.
- Execution scale
SX 3 - Deployment-wide with setup
The exploit must be delivered to each reachable robot; it does not provide a separate fleet orchestration mechanism.
- Recovery burden
OR 4 - Fleet action or replacement
Persistence via hotkey-bound scripts surviving reboot, must be manually cleared from and unitree and etc and programming and.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:4/DP:3/AT:3/CH:4/SR:3/SX:3/OR:4/EV:3/LS:PATCH_AVAILABLERead the scoring method →Privacy · Co-dominant path
Perception privacy
Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.
Proximity or local access
The attacker must reach the robot’s exposed DDS service on the local or deployment network.
EvidenceNVD
Cross-domain authority chain
Reusable bridge crossing device and cloud and physical boundaries.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception privacy
Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Persistence requires manual cleanup.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
The attacker must reach the robot’s exposed DDS service on the local or deployment network.
- Execution complexity
EC 3 - Reproducible exploit workflow
The same unauthenticated DDS programming message yields root execution; accessing camera, LIDAR, and spatial state needs no additional vulnerability.
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Live sensor access reveals people and surroundings but does not independently command physical motion.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.
- Authority
AT 3 - Administrative or command authority
Operating-system root provides sensor access, though this privacy path does not claim a vendor signing key.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Reusable bridge crossing device and cloud and physical boundaries.
- Reuse scale
SR 3 - Portable product-class technique
Technique reuses fleet-wide.
- Execution scale
SX 3 - Deployment-wide with setup
The root-and-sensor workflow can be repeated across reachable affected robots after the required network setup.
- Recovery burden
OR 4 - Fleet action or replacement
Persistence requires manual cleanup.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:3/EX:2/PH:2/DP:4/AT:3/CH:4/SR:3/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE recordsCVE-2026-27509
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509) at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509). Reported attack vector: Network (DDS, local network / same DDS domain).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:4/DP:3/AT:3/CH:4/SR:3/SX:3/OR:4/EV:3/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL → assessed CRITICAL.
Unauthenticated DDS publish on domain 0 (local-net/RF-style join, RE:2) carrying api_id=1002 arbitrary Python executed as root via subprocess in the actuator_manager path. Researcher published full repro, no auth bypass needed (EC:3). Root + actuator control gives direct dangerous motion command capability = credible physical safety harm (PH:4). AT:3 = root/service authority modifying/executing arbitrary code, not a signing-root/OTA-root so not 4. Crosses network/device/physical/safety boundaries and RCE+persistence is a reusable bridge (CH:4, boundary_crossing). SR:3 identical flaw reuses across all affected firmware (technique/artifact portability) but no shared secret/key. SX:3 deployment-wide with DDS-domain setup, not self-propagating fleet-scale. Persistence via hotkey-bound scripts surviving reboot, must be manually cleared from /unitree/etc/programming/ (OR:4). Reproduced (EV:3), patched/mitigated by disabling DDS discovery in V1.1.11.
PERCEPTION_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:3/EX:2/PH:4/DP:4/AT:3/CH:4/SR:3/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=HIGH → base CRITICAL · caps privacy-only cap → assessed CRITICAL.
- Same unauthenticated DDS RCE positioning (RE:2, EC:3). Root execution grants full access to onboard live camera and LIDAR / spatial-sensor state and exfiltration (DP:4 world-model/live-camera/nav sensor state).
- perception_feeds_action — true because these same perception streams drive the robot’s navigation and motion decisions, and root can manipulate them. AT:3 root/service authority. PH:2 = surveillance/perception exposure, no direct severe harm on this path. CH:4 reusable bridge crossing device/cloud/physical boundaries (boundary_crossing). SR:3 technique reuses fleet-wide, SX:3 deployment-wide. OR:4 persistence requires manual cleanup. EV:2 (perception/exfil impact is reasoned/report-backed rather than the explicitly reproduced demo, which centered on code execution).
Published baseline
- v4.0 8.5 HIGH —
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X— VulnCheck via NVD - v3.1 8 HIGH —
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H— VulnCheck via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0024 (“Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509)”), paths.cfse.ai/CPATH-2026-0024 (published 2026-06-03).