Impact
Google Turbinia allows an attacker who can submit a processing request or influence an evidence path or name to execute arbitrary commands on the worker fleet. The flaw is an OS command injection (CWE‑78). If successful, the attacker can compromise the entire worker cluster, gaining full access to the infrastructure that stores and processes forensic evidence. The impact extends across confidentiality, integrity, and availability, potentially affecting all stakeholders handled by Turbinia services.
Affected Systems
This vulnerability affects the Google Turbinia platform. Specific product names mentioned are Google:Turbinia; the input does not provide a list of affected CPEs or version ranges beyond the fact that the fix was released on 2026‑07‑10. Users of older Turbinia releases prior to this date are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk. The EPSS score of less than 1% suggests a very low yet non‑zero likelihood of exploitation in the wild at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog, implying there is no known large‑scale exploitation trend. The likely attack vector is via authenticated requests that an attacker can control or influence: the attacker needs permissions to submit a processing request or otherwise alter the evidence path/name. Once the malicious payload is injected, it is executed with the privileges of the Turbinia worker process, leading to full code execution on the fleet.
OpenCVE Enrichment