Description
Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Turbinia allows an attacker who can submit a processing request or influence an evidence path or name to execute arbitrary commands on the worker fleet. The flaw is an OS command injection (CWE‑78). If successful, the attacker can compromise the entire worker cluster, gaining full access to the infrastructure that stores and processes forensic evidence. The impact extends across confidentiality, integrity, and availability, potentially affecting all stakeholders handled by Turbinia services.

Affected Systems

This vulnerability affects the Google Turbinia platform. Specific product names mentioned are Google:Turbinia; the input does not provide a list of affected CPEs or version ranges beyond the fact that the fix was released on 2026‑07‑10. Users of older Turbinia releases prior to this date are at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity risk. The EPSS score of less than 1% suggests a very low yet non‑zero likelihood of exploitation in the wild at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog, implying there is no known large‑scale exploitation trend. The likely attack vector is via authenticated requests that an attacker can control or influence: the attacker needs permissions to submit a processing request or otherwise alter the evidence path/name. Once the malicious payload is injected, it is executed with the privileges of the Turbinia worker process, leading to full code execution on the fleet.

Generated by OpenCVE AI on August 12, 2026 at 21:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Turbinia patch released on 2026‑07‑10 or a later version that contains this fix
  • Ensure that only trusted users have the ability to submit processing requests or modify evidence paths; apply strict role‑based access controls
  • Place the Turbinia worker nodes behind network isolation layers and monitor for anomalous shell process launches

Generated by OpenCVE AI on August 12, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google turbinia
Vendors & Products Google
Google turbinia

Tue, 11 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
Title Google Turbinia arbitrary command execution
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-08-17T18:18:07.323Z

Reserved: 2026-07-28T15:01:46.486Z

Link: CVE-2026-67180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:34.257

Modified: 2026-08-26T16:52:20.850

Link: CVE-2026-67180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')