Arbitrary Command Execution in Google Turbinia
CVE-2026-67180
7.5HIGH
What is CVE-2026-67180?
Google Turbinia is susceptible to arbitrary command execution through its worker tasks. An attacker with the necessary privileges to submit a processing request or manipulate evidence paths can execute code on the worker fleet. This vulnerability exposes systems to potential unauthorized actions, emphasizing the importance of timely updates and security patches.
Affected Version(s)
Turbinia 0
Turbinia 0 < 2026-07-10
Turbinia 2026-07-10