CPATH-2026-0024 · Robotics / humanoid

Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509)

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsDevice-control safety + Perception privacy

These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    carrying api_id is 1002 arbitrary Python executed as root via subprocess in the actuator_manager path.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Crosses network and device and physical and safety boundaries and remote code execution and persistence is a reusable bridge.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Persistence via hotkey-bound scripts surviving reboot, must be manually cleared from and unitree and etc and programming and.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

carrying api_id is 1002 arbitrary Python executed as root via subprocess in the actuator_manager path.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Researcher published full repro, without authentication bypass needed.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Root code execution exposes the robot's motion commands, actuator state, and connected sensor state as part of the control path.

Model inference
AuthorityAT 3
Administrative or command authority

Remote code execution reaches operating-system and robot-service authority, including motion control, but not the firmware-signing root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Crosses network and device and physical and safety boundaries and remote code execution and persistence is a reusable bridge.

Model inference
Reuse scaleSR 3
Portable product-class technique

Identical flaw reuses across all affected firmware (technique and artifact portability) but no shared secret and key.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

The exploit must be delivered to each reachable robot; it does not provide a separate fleet orchestration mechanism.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Persistence via hotkey-bound scripts surviving reboot, must be manually cleared from and unitree and etc and programming and.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unauthenticated root execution reaches actuator commands, allowing unsafe robot motion that can endanger nearby people.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:4/DP:3/AT:3/CH:4/SR:3/SX:3/OR:4/EV:3/LS:PATCH_AVAILABLERead the scoring method →

Privacy · Co-dominant path

Perception privacy

Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    The attacker must reach the robot’s exposed DDS service on the local or deployment network.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Reusable bridge crossing device and cloud and physical boundaries.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception privacy

    Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Persistence requires manual cleanup.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The attacker must reach the robot’s exposed DDS service on the local or deployment network.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

The same unauthenticated DDS programming message yields root execution; accessing camera, LIDAR, and spatial state needs no additional vulnerability.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Live sensor access reveals people and surroundings but does not independently command physical motion.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.

Model inference
AuthorityAT 3
Administrative or command authority

Operating-system root provides sensor access, though this privacy path does not claim a vendor signing key.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Reusable bridge crossing device and cloud and physical boundaries.

Model inference
Reuse scaleSR 3
Portable product-class technique

Technique reuses fleet-wide.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

The root-and-sensor workflow can be repeated across reachable affected robots after the required network setup.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Persistence requires manual cleanup.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Root execution exposes live camera, LIDAR, navigation, and spatial-sensor data that describe the robot’s surroundings.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:3/EX:2/PH:2/DP:4/AT:3/CH:4/SR:3/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v4.0 · 8.5 HIGHVulnCheck via NVD
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
v3.1 · 8 HIGHVulnCheck via NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509) at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509). Reported attack vector: Network (DDS, local network / same DDS domain).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:4/DP:3/AT:3/CH:4/SR:3/SX:3/OR:4/EV:3/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL → assessed CRITICAL.

Unauthenticated DDS publish on domain 0 (local-net/RF-style join, RE:2) carrying api_id=1002 arbitrary Python executed as root via subprocess in the actuator_manager path. Researcher published full repro, no auth bypass needed (EC:3). Root + actuator control gives direct dangerous motion command capability = credible physical safety harm (PH:4). AT:3 = root/service authority modifying/executing arbitrary code, not a signing-root/OTA-root so not 4. Crosses network/device/physical/safety boundaries and RCE+persistence is a reusable bridge (CH:4, boundary_crossing). SR:3 identical flaw reuses across all affected firmware (technique/artifact portability) but no shared secret/key. SX:3 deployment-wide with DDS-domain setup, not self-propagating fleet-scale. Persistence via hotkey-bound scripts surviving reboot, must be manually cleared from /unitree/etc/programming/ (OR:4). Reproduced (EV:3), patched/mitigated by disabling DDS discovery in V1.1.11.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:3/EX:2/PH:4/DP:4/AT:3/CH:4/SR:3/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=HIGH → base CRITICAL · caps privacy-only cap → assessed CRITICAL.

  • Same unauthenticated DDS RCE positioning (RE:2, EC:3). Root execution grants full access to onboard live camera and LIDAR / spatial-sensor state and exfiltration (DP:4 world-model/live-camera/nav sensor state).
  • perception_feeds_action — true because these same perception streams drive the robot’s navigation and motion decisions, and root can manipulate them. AT:3 root/service authority. PH:2 = surveillance/perception exposure, no direct severe harm on this path. CH:4 reusable bridge crossing device/cloud/physical boundaries (boundary_crossing). SR:3 technique reuses fleet-wide, SX:3 deployment-wide. OR:4 persistence requires manual cleanup. EV:2 (perception/exfil impact is reasoned/report-backed rather than the explicitly reproduced demo, which centered on code execution).

Published baseline

  • v4.0 8.5 HIGH — CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X — VulnCheck via NVD
  • v3.1 8 HIGH — CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H — VulnCheck via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0024 (“Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509)”), paths.cfse.ai/CPATH-2026-0024 (published 2026-06-03).